Dynamic Access Control for Business Process Logs

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current access control methods for process data streams are inefficient as they rely on static views and manual mapping of access rights, which does not allow for dynamic or real-time updating, and are not suitable for dynamically changing information flows, leading to issues in maintaining data integrity and user-specific access in complex business processes.

Innovation Solution

A dynamic filter construction technique that continuously updates access control policies and applies only relevant filters to the data stream, enabling personalized event flows based on user permissions and maintaining data integrity by encoding access rights in a machine-readable format using XACML, allowing for real-time adaptation and efficient online filtering.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If static views and manual mapping of access rights are used, then access control can be implemented, but the system cannot dynamically update access rights in real-time and cannot adapt to dynamically changing information flows

Engineering Contradiction:
Improvedynamic updating of access rightsVSAvoidaccess control system complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent transforms static access control views into dynamic ones by continuously updating views based on changing data stream characteristics and user permissions. The system monitors data stream dynamics and automatically adjusts access control views in real-time, enabling adaptability to changing information flows without manual intervention.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent introduces an intermediary component that acts as a bridge between the data stream and access control mechanisms. This intermediary continuously analyzes the data stream, determines relevant access rights dynamically, and generates appropriate views, thereby resolving the contradiction between adaptability and complexity by automating the mediation process.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If all access control policies are applied to the entire data stream, then comprehensive access control is achieved, but processing efficiency decreases due to unnecessary filtering operations

Engineering Contradiction:
Improvedata processing efficiencyVSAvoidaccess control enforcement completeness
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent applies partial action by selectively applying only the subset of access control policies that are relevant to each specific data element or stream segment. Instead of enforcing all policies uniformly across the entire data stream, the system dynamically determines which policies apply to which data portions, thereby maintaining access control reliability while significantly improving processing efficiency by avoiding unnecessary filtering operations.

Inventive Principle:
Principle #16Partial or excessive action

3Adaptability or versatility

If manual mapping of access rights to process data is performed, then access control can be established, but the system cannot adapt to evolving business processes and requires continuous manual updates

Engineering Contradiction:
Improveadaptation to evolving business processesVSAvoidtime for manual updates
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The patent implements self-service by enabling the access control system to automatically adapt to evolving business processes without manual intervention. The system continuously monitors the data stream, automatically determines changing access requirements based on observed patterns and user permissions, and dynamically updates access control views itself, thereby eliminating the need for manual mappings and continuous manual updates while maintaining high adaptability.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP3084675B1Data access control for business processes
Publication Date: 2018.02.07 EMIRATES TELECOMMUNICATIONS CORPORATION
  • EP3084675B1 patent drawingFigure 1
  • EP3084675B1 patent drawingFigure 2
  • EP3084675B1 patent drawingFigure 3

AI summary

The invention relates to a method and system which provides access control and access control enforcement particularly in relation to business process data streams. Embodiments of the invention provide a method and a set of components (referred to as: Policy Administration Point, Policy Enforcement Point, Filter Updater, Log De-Multiplexer) for fast online filtering of process logs based on access rights. In one embodiment the method comprises a series of steps to (i) encode each user's access rights to the process log in a machine readable format (ii) use such encoding together with incoming process events to compute a custom online filter to be applied to the process log as it is being recorded (iii) execute logical log de-multiplexing, enabling each user to query, inspect and monitor a separate event flow. In specific embodiments, the four components are virtual devices, respectively in charge of policy encoding (Policy Administration Point), policy evaluation and enforcement (Policy Enforcement Point), computation of an online filter with enforcement of log integrity constraints (Filter Updater), and generation of virtual event flows and support for policy changes and rights' revocations (Log De-Multiplexer).