Dynamic Hierarchical Access Control for Organizational Data
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing organization management systems face challenges in dynamically managing access to hierarchical organization data, leading to inflexible access control and increased administrative burdens due to rigid hierarchical relationships, which limits real-time changes and 'what-if' scenario testing.
Innovation Solution
A graphical user interface system that processes organizational data in a hierarchical format, using dynamic role assignment and real-time access control policies to allow users to change their access levels by modifying chart user IDs and role assignment rules, eliminating the need for persistent access control lists.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If rigid hierarchical access control is implemented to ensure data security, then data security is improved, but organizational flexibility and real-time access management deteriorate
Solution Approach 1:
The patent implements dynamic access control where the system automatically recalculates hierarchical relationships and access rights in real-time based on current organizational structure. When organizational changes occur (additions, deletions, promotions), the system dynamically updates access permissions without manual intervention, allowing both security maintenance and organizational flexibility. This resolves the contradiction by making access control adaptive rather than static.
Solution Approach 2:
The system performs self-service by automatically recalculating access rights and hierarchical relationships when organizational changes occur. Instead of requiring manual administrative updates, the system autonomously processes changes, updates access control lists, and maintains security policies. This eliminates the need for rigid pre-defined access control lists while maintaining security, thereby improving both data security and organizational flexibility simultaneously.
2Reliability
If complete access control lists are persisted for every user to ensure security, then data security is improved, but system complexity and processing overhead increase
Solution Approach 1:
The patent extracts and removes the need for persisting complete access control lists for every user. Instead of storing comprehensive ACLs in the database, the system calculates access rights on-demand based on hierarchical relationships. This extraction eliminates the complexity and storage overhead associated with maintaining persistent ACLs while maintaining security through real-time calculation of access permissions based on current organizational structure.
Solution Approach 2:
The system creates a virtual copy of access control information by calculating it dynamically from hierarchical relationships rather than storing actual ACLs. When access control is needed, the system generates the appropriate permissions by evaluating the user's position in the hierarchy and the relevant organizational relationships. This copying approach avoids the complexity of storing and managing persistent ACLs while maintaining security.
3Reliability
If hierarchical relationships are recalculated for each organizational change to maintain access control, then data security is improved, but processing time and resource overhead increase
Solution Approach 1:
The patent implements continuous access control maintenance by automatically triggering recalculation operations whenever organizational changes occur. Instead of periodic or manual updates, the system continuously monitors for changes (additions, deletions, promotions) and immediately recalculates affected access rights. This continuous action ensures access control accuracy is maintained without manual intervention while minimizing delays through automated real-time processing.
Solution Approach 2:
The system performs preliminary actions by establishing event-driven triggers that automatically initiate recalculation operations when organizational changes occur. When a change event is detected (such as a promotion or department reorganization), the system preemptively recalculates access rights before they are needed, ensuring security is maintained without waiting for access requests. This preliminary action reduces processing delays by being proactive rather than reactive.
Data Source
AI summary
Embodiments are described for a system and method of controlling access to information in an organization by defining a hierarchical organizational structure of boxes, and security configuration comprising user records, security roles, rules to map users to boxes, and rules to grant roles to users via mapped boxes. Access control is applied in the context of a defined organizational structure using the effective set of access control policies computed in real time per each data access request from any given user.


