Dynamic Hierarchical Access Control for Organizational Data

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing organization management systems face challenges in dynamically managing access to hierarchical organization data, leading to inflexible access control and increased administrative burdens due to rigid hierarchical relationships, which limits real-time changes and 'what-if' scenario testing.

Innovation Solution

A graphical user interface system that processes organizational data in a hierarchical format, using dynamic role assignment and real-time access control policies to allow users to change their access levels by modifying chart user IDs and role assignment rules, eliminating the need for persistent access control lists.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If rigid hierarchical access control is implemented to ensure data security, then data security is improved, but organizational flexibility and real-time access management deteriorate

Engineering Contradiction:
Improvedata securityVSAvoidorganizational flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic access control where the system automatically recalculates hierarchical relationships and access rights in real-time based on current organizational structure. When organizational changes occur (additions, deletions, promotions), the system dynamically updates access permissions without manual intervention, allowing both security maintenance and organizational flexibility. This resolves the contradiction by making access control adaptive rather than static.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system performs self-service by automatically recalculating access rights and hierarchical relationships when organizational changes occur. Instead of requiring manual administrative updates, the system autonomously processes changes, updates access control lists, and maintains security policies. This eliminates the need for rigid pre-defined access control lists while maintaining security, thereby improving both data security and organizational flexibility simultaneously.

Inventive Principle:
Principle #25Self-service

2Reliability

If complete access control lists are persisted for every user to ensure security, then data security is improved, but system complexity and processing overhead increase

Engineering Contradiction:
Improvedata securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts and removes the need for persisting complete access control lists for every user. Instead of storing comprehensive ACLs in the database, the system calculates access rights on-demand based on hierarchical relationships. This extraction eliminates the complexity and storage overhead associated with maintaining persistent ACLs while maintaining security through real-time calculation of access permissions based on current organizational structure.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system creates a virtual copy of access control information by calculating it dynamically from hierarchical relationships rather than storing actual ACLs. When access control is needed, the system generates the appropriate permissions by evaluating the user's position in the hierarchy and the relevant organizational relationships. This copying approach avoids the complexity of storing and managing persistent ACLs while maintaining security.

Inventive Principle:
Principle #26Copying

3Reliability

If hierarchical relationships are recalculated for each organizational change to maintain access control, then data security is improved, but processing time and resource overhead increase

Engineering Contradiction:
Improveaccess control accuracyVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements continuous access control maintenance by automatically triggering recalculation operations whenever organizational changes occur. Instead of periodic or manual updates, the system continuously monitors for changes (additions, deletions, promotions) and immediately recalculates affected access rights. This continuous action ensures access control accuracy is maintained without manual intervention while minimizing delays through automated real-time processing.

Inventive Principle:
Principle #20Continuity of useful action

Solution Approach 2:

The system performs preliminary actions by establishing event-driven triggers that automatically initiate recalculation operations when organizational changes occur. When a change event is detected (such as a promotion or department reorganization), the system preemptively recalculates access rights before they are needed, ensuring security is maintained without waiting for access requests. This preliminary action reduces processing delays by being proactive rather than reactive.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8793489B2Method and system for controlling data access to organizational data maintained in hierarchical
Publication Date: 2014.07.29 SABA SOFTWARE INC
  • US8793489B2 patent drawing
  • US8793489B2 patent drawing
  • US8793489B2 patent drawing

AI summary

Embodiments are described for a system and method of controlling access to information in an organization by defining a hierarchical organizational structure of boxes, and security configuration comprising user records, security roles, rules to map users to boxes, and rules to grant roles to users via mapped boxes. Access control is applied in the context of a defined organizational structure using the effective set of access control policies computed in real time per each data access request from any given user.