Dynamic Authorization Hierarchies for Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current access control methods in IT systems, such as role-based systems, are inflexible and lack clarity in assigning responsibilities, leading to delays in revoking access rights and exposing sensitive data due to technical administrators having unrestricted access.

Innovation Solution

A dynamic authorization hierarchy system where users assign access rights to others, creating independent hierarchies based on roles, ownership, and attributes, ensuring that access is granted only when multiple conditions are met, thereby enhancing security and flexibility.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If role-based access control systems are used, then access control is simplified, but it becomes impossible to trace which user was responsible for a specific data change

Engineering Contradiction:
Improveaccess control simplificationVSAvoiduser responsibility traceability
Core Design Contradiction:
Ease of operationVSLoss of information

Solution Approach 1:

The patent segments the access control system into multiple independent authorization hierarchies rather than using a single role-based system. Each hierarchy is traced back to a specific user who created it, maintaining full auditability while simplifying access control operations. This segmentation allows the system to preserve user responsibility traceability without compromising ease of operation.

Inventive Principle:
Principle #1Segmentation

2Reliability

If technical administrators have unrestricted access to all company data, then data availability is ensured, but the risk of sensitive data leakage increases

Engineering Contradiction:
Improvedata availabilityVSAvoiddata leakage risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent divides the monolithic administrator access into multiple segmented authorization hierarchies. Each hierarchy is created and controlled by specific users, limiting the scope of access rights. This segmentation ensures data availability through multiple access paths while reducing the risk of data leakage by preventing any single administrator from having unrestricted access to all data.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces authorization hierarchies as intermediary structures between data owners and access requests. These hierarchies mediate the access control process, allowing data to remain available to authorized users while preventing unauthorized access. The hierarchies act as intermediaries that translate broad data availability requirements into specific, traceable access permissions.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If access rights are revoked through hierarchical delegation, then centralized control is maintained, but significant delays occur due to multiple approval levels

Engineering Contradiction:
Improvecentralized controlVSAvoidaccess revocation delay
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent makes the authorization hierarchies dynamic and user-initiated rather than static and administrator-controlled. Users can create and modify their own authorization hierarchies, enabling rapid access right assignments and revocations without waiting for hierarchical approval. This dynamic approach maintains centralized control through the hierarchy structure while dramatically reducing the time required for access management operations.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent enables users to perform access control operations themselves by creating and managing their own authorization hierarchies. This self-service capability allows users to assign and revoke access rights independently, eliminating the delays associated with multi-level administrative approval while maintaining the structural control provided by the hierarchy system.

Inventive Principle:
Principle #25Self-service

4Productivity

If managers intervene directly in IT administrative tasks, then response speed increases, but managers become overloaded and technical capabilities are compromised

Engineering Contradiction:
Improveresponse speedVSAvoidmanager workload
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent enables technical administrators and users to perform IT administrative tasks independently through the authorization hierarchy system. Users can create hierarchies, assign rights, and manage access without requiring manager intervention. This self-service approach maintains rapid response capability while preventing manager overload, as technical operations are performed by the appropriate technical personnel rather than business managers.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent introduces authorization hierarchies as intermediary structures that mediate between business needs and IT implementation. These hierarchies allow technical administrators to translate business requirements into access control configurations independently, eliminating the need for managers to directly perform technical tasks while maintaining responsive business-IT alignment.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP3539044B1Access control for data objects
Publication Date: 2021.08.18 BUNDESDRUCKEREI GMBH
  • EP3539044B1 patent drawingFigure 1
  • EP3539044B1 patent drawingFigure 2
  • EP3539044B1 patent drawingFigure 3~4

AI summary

The invention relates to a method for access control for data objects (106, 108, 110, 112, 114, 116). A first authorisation hierarchy is provided (1002) that is dynamic starting from a first user through a plurality of users. The first authorisation hierarchy is produced gradually in this case by virtue of, starting from the first user, the last user respectively included in the first authorisation hierarchy personally allocating a first access right to a user who is to be newly included, so that each user comprised by the first authorisation hierarchy is allocated the first access right. The first authorisation hierarchy comprises at least two further users besides the first user. Further, an outbound second authorisation hierarchy produced by a second user is provided (1004). This second authorisation hierarchy is produced gradually by virtue of, starting from the second user, the last user respectively included in the second authorisation hierarchy personally allocating a second access right to a user who is to be newly included, so that each user comprised by the second authorisation hierarchy is allocated the second access right. The second authorisation hierarchy comprises at least one further user besides the second user. A user is granted access to one of the data objects only if the applicable user is comprised both by the first authorisation hierarchy, so that he is allocated the first access right, and by the second authorisation hierarchy, so that he is further allocated the second access right.