Dynamic Metadata Access Control via Pseudo-User Matching
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing enterprise content management systems lack a dynamic and controlled method for managing access rights to metadata, leading to inconsistent and static access permissions that do not adapt to the specific properties of electronic objects.
Innovation Solution
A method and apparatus that allow for dynamic control of access to metadata by determining pseudo-users and their access modes based on property values, enabling granular permissions for individual properties, including read, edit, or full access, and denying access as needed, using both direct and indirect metadata properties.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If static access permissions are used for metadata, then access control is simple to implement, but adaptability to different electronic objects and properties is poor
Solution Approach 1:
The patent implements dynamic access control by allowing permissions to change based on the electronic object's properties and user characteristics. Instead of static permissions, the system dynamically determines access rights by evaluating metadata properties (e.g., document type, sensitivity level) and user attributes (e.g., role, department) in real-time, enabling the access control mechanism to adapt to different electronic objects and situations.
Solution Approach 2:
The patent applies local quality by enabling different access permissions for different metadata properties within the same electronic object. Rather than uniform access control, the system allows granular permission settings where specific properties (e.g., creation date, author, content) can have different access levels for different users, allowing fine-grained control over which properties are visible or editable.
2Measurement precision
If granular permissions for individual properties are implemented, then access control precision is improved, but system complexity increases
Solution Approach 1:
The patent segments access control into property-level permissions, allowing independent control of each metadata property. Instead of managing access at the document level, the system divides permissions into discrete property-level settings (e.g., who can view creation date, who can edit author information), enabling precise control over individual properties while maintaining manageable organization through structured permission categories.
Solution Approach 2:
The patent implements a universal access control framework that handles multiple scenarios through a single system. The same permission evaluation mechanism works for different electronic object types (documents, images, videos) and different property types (temporal, spatial, metadata), providing multi-functional access control without requiring separate systems for each scenario.
3Reliability
If dynamic access control based on metadata values is used, then security of sensitive information is improved, but processing time for access requests increases
Solution Approach 1:
The patent applies preliminary action by pre-defining access rules and permission templates before actual access requests occur. The system pre-establishes the evaluation criteria and permission frameworks, so when access requests arrive, the system only needs to match the request against pre-defined rules rather than creating access decisions from scratch, reducing processing time while maintaining security.
Solution Approach 2:
The patent implements feedback mechanisms where the access control system continuously learns from access patterns and user behavior. The system monitors how users interact with metadata and adjusts permission evaluations accordingly, improving accuracy of access decisions over time and reducing unnecessary processing by learning which requests are likely to be authorized based on historical patterns.
Data Source
AI summary
A method for controlling access to metadata or a property in metadata of an electronic object comprises receiving a request from an identified user to access metadata of an electronic object; determining one or more pseudo-users that are allowed to access the requested metadata of the electronic object and their corresponding access modes; retrieving at least one person identity by utilizing at least one property value of one or more properties of the electronic object, which one or more properties correspond to the determined one or more pseudo-users; comparing the identity of the requesting identified user to the retrieved person identities, and if there is a match; providing to the requesting identified user an access to selected properties in the metadata, which selected properties are determined according to the access mode. The invention also relates to a method for defining access to metadata of an electronic object.


