Distributed Policy Management for Scalable Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional centralized approaches to managing and enforcing access control policies in distributed information systems become inefficient and resource-intensive as the systems scale, particularly in large distributed environments like the semantic web, where trillions of resources and corresponding data types require complex policy management and enforcement.

Innovation Solution

The system introduces distributed policy management and enforcement by defining localized access control policies at each domain within the information system, allowing each domain to operate independently with its own schema and policies, reducing reliance on centralized components and enabling flexible management and enforcement of access control.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If centralized policy management is used, then policy enforcement consistency is maintained, but system scalability and resource efficiency deteriorate as the information system grows to trillions of resources

Engineering Contradiction:
Improvesystem scalabilityVSAvoidcentralized management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the centralized policy management system into distributed domain-specific policy managers. Each domain (e.g., enterprise domain, government domain) has its own policy manager that independently manages policies for resources within that domain. This segmentation allows the system to scale to trillions of resources without requiring a single centralized management point, as each domain can be managed autonomously while still participating in the federated system.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a federated dimension to policy management, moving from a single-dimensional centralized hierarchy to a multi-dimensional federated structure. Policy managers operate at the domain level (one dimension) while the federation framework provides cross-domain coordination (another dimension). This dimensional expansion allows scalable management of vast resource spaces without the bottlenecks of centralized control.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Productivity

If localized domain policies are implemented, then resource burden and dependencies on centralized definitions are reduced, but policy coordination and consistency across domains become more challenging

Engineering Contradiction:
Improvepolicy management efficiencyVSAvoidpolicy coordination reliability
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

Each domain's policy manager operates autonomously, making policy decisions independently based on local domain requirements without requiring constant consultation with centralized authorities. This self-service capability reduces the resource burden on centralized systems and eliminates dependencies on centralized data type definitions, while the federation framework ensures that autonomous decisions remain coordinated through standardized interfaces and mutual recognition agreements.

Inventive Principle:
Principle #25Self-service

3Adaptability or versatility

If independent domain policy management is enabled, then flexibility and adaptability improve, but system-wide policy consistency and integration become more difficult

Engineering Contradiction:
Improvedomain policy flexibilityVSAvoidsystem integration complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements universal interfaces and standardized communication protocols that allow diverse, independent domain policy managers to interact through common mechanisms. The federation framework provides multi-functional capabilities including policy translation, mutual recognition, and coordinated enforcement across different domain types. This universality enables high flexibility within domains while managing integration complexity through standardized interaction patterns.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS8893215B2Method and apparatus for providing distributed policy management
Publication Date: 2014.11.18 NOKIA TECHNOLOGIES OY
  • US8893215B2 patent drawing
  • US8893215B2 patent drawing
  • US8893215B2 patent drawing

AI summary

An approach is provided for distributed policy management and enforcement. A policy manager determines one or more domains of an information system. The one or more domains are associated at least in part with respective subsets of one or more resources of the information system. The policy manager also determines one or more respective access policies local to the one or more domains. The one or more respective access policies configured to enable a determination at least in part of access to the respective subsets, the one or more resources, or a combination thereof. At least one of the one or more respective access policies is configured to operate independently of other ones of the one or more respective schemas.