Dynamic Access Control via Virtual Anchors

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In on-demand services environments, existing access control systems struggle to dynamically manage access to resources based on specific request actions, leading to potential security vulnerabilities and inefficiencies in multi-tenant database systems.

Innovation Solution

The implementation of a dynamic access control mechanism that uses anchorless rules and Virtual Access Check (VAC) rules to selectively enforce access controls based on request actions, allowing for real-time evaluation and blocking of requests, thereby enhancing security and resource management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional access control systems are used in on-demand services environments, then system simplicity is maintained, but security vulnerabilities increase and access control adaptability decreases

Engineering Contradiction:
ImprovesecurityVSAvoidaccess control system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements dynamic access control rules that can be evaluated in real-time based on request actions. The system transitions from static access control configurations to dynamic rule evaluation that adapts to specific request contexts, allowing security policies to change based on runtime conditions without requiring system redesign.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The access control mechanism is segmented into distinct rule types (anchorless rules and Virtual Access Check rules) that can be independently configured and evaluated. This segmentation allows the system to apply different access control strategies to different request scenarios, improving security without requiring complete system complexity.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If dynamic access control rules are implemented, then access control adaptability improves, but system complexity increases

Engineering Contradiction:
Improveaccess control adaptabilityVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary access control evaluation layer that sits between request processing and resource access. This intermediary layer handles the complexity of dynamic rule evaluation, allowing the rest of the system to remain relatively simple while gaining advanced adaptability through the mediating rule evaluation mechanism.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If real-time request evaluation is performed, then security response time improves, but processing speed decreases

Engineering Contradiction:
Improvesecurity responseVSAvoidrequest processing speed
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

The system performs preliminary evaluation of access control rules before executing request processing. By evaluating anchorless rules and Virtual Access Check rules in advance, the system can quickly determine whether requests should be allowed or blocked, avoiding the need for complex real-time analysis during critical processing paths.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11683318B2Dynamic deployment of access controls anchored on request actions
Publication Date: 2023.06.20 SALESFORCE INC
  • US11683318B2 patent drawing
  • US11683318B2 patent drawing
  • US11683318B2 patent drawing

AI summary

Techniques and structures to provide dynamic deployment of access controls in an on-demand environment. A host electronic device may comprise one or more processors coupled with the at least one physical memory device, the one or more processors configurable to receive, via a user interface, request to access one or more resources managed by the electronic device in the multi-user, on demand computing environment, the request comprising one or more request elements, determine whether a virtual access rule logic comprises one or more virtual access check rules which are anchored to the one or more request elements, and in response to a determination that the virtual access rule logic comprises one or more virtual access check rules which are anchored to the one or more request elements, apply the one or more virtual access check rules to the request. Additional subject matter may be described and claimed.