Dynamic Authorization Hierarchies for Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current access control methods in IT systems, such as role-based systems, are inflexible and lack clarity in assigning responsibilities, leading to delays in revoking access rights and exposing sensitive data due to technical administrators having unrestricted access.
Innovation Solution
A dynamic authorization hierarchy system where users assign access rights to others, creating independent hierarchies based on roles, ownership, and attributes, ensuring that access is granted only when multiple conditions are met, thereby enhancing security and flexibility.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If role-based access control systems are used, then access control is simplified, but it becomes impossible to trace which user was responsible for a specific data change
Solution Approach 1:
The patent segments the access control system into multiple independent authorization hierarchies rather than using a single role-based system. Each hierarchy is traced back to a specific user who created it, maintaining full auditability while simplifying access control operations. This segmentation allows the system to preserve user responsibility traceability without compromising ease of operation.
2Reliability
If technical administrators have unrestricted access to all company data, then data availability is ensured, but the risk of sensitive data leakage increases
Solution Approach 1:
The patent divides the monolithic administrator access into multiple segmented authorization hierarchies. Each hierarchy is created and controlled by specific users, limiting the scope of access rights. This segmentation ensures data availability through multiple access paths while reducing the risk of data leakage by preventing any single administrator from having unrestricted access to all data.
Solution Approach 2:
The patent introduces authorization hierarchies as intermediary structures between data owners and access requests. These hierarchies mediate the access control process, allowing data to remain available to authorized users while preventing unauthorized access. The hierarchies act as intermediaries that translate broad data availability requirements into specific, traceable access permissions.
3Reliability
If access rights are revoked through hierarchical delegation, then centralized control is maintained, but significant delays occur due to multiple approval levels
Solution Approach 1:
The patent makes the authorization hierarchies dynamic and user-initiated rather than static and administrator-controlled. Users can create and modify their own authorization hierarchies, enabling rapid access right assignments and revocations without waiting for hierarchical approval. This dynamic approach maintains centralized control through the hierarchy structure while dramatically reducing the time required for access management operations.
Solution Approach 2:
The patent enables users to perform access control operations themselves by creating and managing their own authorization hierarchies. This self-service capability allows users to assign and revoke access rights independently, eliminating the delays associated with multi-level administrative approval while maintaining the structural control provided by the hierarchy system.
4Productivity
If managers intervene directly in IT administrative tasks, then response speed increases, but managers become overloaded and technical capabilities are compromised
Solution Approach 1:
The patent enables technical administrators and users to perform IT administrative tasks independently through the authorization hierarchy system. Users can create hierarchies, assign rights, and manage access without requiring manager intervention. This self-service approach maintains rapid response capability while preventing manager overload, as technical operations are performed by the appropriate technical personnel rather than business managers.
Solution Approach 2:
The patent introduces authorization hierarchies as intermediary structures that mediate between business needs and IT implementation. These hierarchies allow technical administrators to translate business requirements into access control configurations independently, eliminating the need for managers to directly perform technical tasks while maintaining responsive business-IT alignment.
Data Source
Figure 1
Figure 2
Figure 3~4
AI summary
The invention relates to a method for access control for data objects (106, 108, 110, 112, 114, 116). A first authorisation hierarchy is provided (1002) that is dynamic starting from a first user through a plurality of users. The first authorisation hierarchy is produced gradually in this case by virtue of, starting from the first user, the last user respectively included in the first authorisation hierarchy personally allocating a first access right to a user who is to be newly included, so that each user comprised by the first authorisation hierarchy is allocated the first access right. The first authorisation hierarchy comprises at least two further users besides the first user. Further, an outbound second authorisation hierarchy produced by a second user is provided (1004). This second authorisation hierarchy is produced gradually by virtue of, starting from the second user, the last user respectively included in the second authorisation hierarchy personally allocating a second access right to a user who is to be newly included, so that each user comprised by the second authorisation hierarchy is allocated the second access right. The second authorisation hierarchy comprises at least one further user besides the second user. A user is granted access to one of the data objects only if the applicable user is comprised both by the first authorisation hierarchy, so that he is allocated the first access right, and by the second authorisation hierarchy, so that he is further allocated the second access right.