Dynamic Policy Model Configuration for ABAC Authorization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Developers face challenges in creating, managing, and collaborating on complex Attribute Based Access Control (ABAC) policies due to their gradual evolution and inherent complexity, making it difficult to efficiently define and enforce access rules across various stakeholders and software platforms.

Innovation Solution

A system and method for dynamic configuration of a policy model as a dynamic authorization implementation, providing interfaces for authors to define policies, generate policy code or policy graph schema, and integrate with Resource Action Inventory, Data-Source Integration, and Permissions Interfaces to create, manage, and enforce access control policies efficiently.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If developers use complex ABAC policies to define access control, then access control capability is improved, but device complexity and difficulty of operation worsen

Engineering Contradiction:
Improveaccess control capabilityVSAvoiddifficulty of creating and managing policies
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces a policy authoring interface as an intermediary tool between developers and complex ABAC policies. This interface provides user-friendly mechanisms for defining access control rules without requiring developers to directly manipulate complex policy syntax, thereby maintaining strong access control capability while improving ease of operation.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system generates policy code or policy graph schema as standardized representations (copies) of access control rules. These generated policies can be directly applied across multiple software platforms, allowing developers to create policies once and reuse them universally, reducing operational complexity while maintaining robust access control.

Inventive Principle:
Principle #26Copying

2Reliability

If developers gradually evolve policies towards ABAC, then access control capability is improved, but loss of time and productivity worsen

Engineering Contradiction:
Improveaccess control capabilityVSAvoidtime for policy creation and management
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent enables developers to define access control policies using simplified initial models and automatically generates the corresponding ABAC policy code. This preliminary action of defining rules in a user-friendly format eliminates the need for gradual evolution through complex syntax, significantly reducing the time required for policy creation while achieving robust ABAC access control.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system replaces the manual, iterative process of gradually evolving policies with an automated mechanism that translates high-level policy definitions into executable ABAC code. This substitution of mechanical policy crafting with automated generation eliminates time-consuming manual adjustments and directly produces production-ready access control policies.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Adaptability or versatility

If policies are defined for multiple stakeholders and platforms, then adaptability is improved, but device complexity worsens

Engineering Contradiction:
Improvemulti-platform access controlVSAvoidpolicy management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent creates a universal policy authoring interface that generates platform-agnostic policy code. This single interface serves multiple functions by producing policies that can be applied across different software platforms and for various stakeholders, thereby achieving multi-platform adaptability without increasing management complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system segments the complex task of multi-platform policy definition into distinct, manageable components through the policy authoring interface. Developers can define policies for specific stakeholders or platforms individually, and the system automatically generates appropriate code for each, reducing overall management complexity while maintaining broad adaptability.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS20240094993A1Method and system for dynamic configuration of a policy model as a dynamic authorization implementation
Publication Date: 2024.03.21 PERMIT IO LTD
  • US20240094993A1 patent drawing
  • US20240094993A1 patent drawing
  • US20240094993A1 patent drawing

AI summary

A method and system for a dynamic configuration of a policy model as a dynamic authorization implementation including a Resource Action Inventory Interface, a Data-Source Integration Interface, a Policy-Sets Interface and a Permissions Interface, wherein an author dynamically creates one or more policies for an application and generates a dynamic authorization implementation. The dynamic authorization implementation is a policy code and/or a policy graph schema. A further method includes the transition from a RBAC policy to an ABAC policy for an application and the generation of a dynamic authorization assignment as a policy code and/or policy graph schema.