Dynamic RBAC Constraints via Context Extraction

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional Role Based Access Control (RBAC) systems lack the ability to utilize context information from all categories, including subject context, and are limited to internal data sources, failing to provide dynamic and sophisticated access control constraints based on subject, object, and environment information.

Innovation Solution

An RBAC method that employs data extraction techniques such as information retrieval, data mining, and natural language processing to gather and analyze content and context from both internal and external sources, enabling dynamic and refined permission constraints on access to objects by considering all combinations of subject, object, and environment information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If traditional Role Based Access Control is used with predefined roles and permissions, then access control implementation is simplified, but the system cannot provide fine-grained dynamic access control based on context information

Engineering Contradiction:
Improveaccess control implementationVSAvoiddynamic access control capability
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The patent transforms static role-based permissions into dynamic context-based permissions. Access rights are no longer fixed to roles but are dynamically determined by evaluating context information (subject attributes, object attributes, environmental conditions) at runtime. This allows the system to adapt access control decisions based on current conditions while maintaining the simplicity of role-based assignment.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes the parameters used for access control from static role definitions to dynamic context parameters. By introducing context information gathering and evaluation mechanisms, the system can adjust access permissions based on varying conditions such as user attributes, object sensitivity, and environmental factors, enabling fine-grained control without complex predefined rules.

Inventive Principle:
Principle #35Parameter changes

2Device complexity

If RBAC systems are limited to internal data sources, then system complexity is reduced, but the ability to gather comprehensive context information is insufficient

Engineering Contradiction:
Improvesystem architectureVSAvoidcontext information completeness
Core Design Contradiction:
Device complexityVSLoss of information

Solution Approach 1:

The patent introduces context information gathering mechanisms that act as intermediaries between the RBAC system and both internal and external data sources. These mechanisms collect context information from multiple sources (user profiles, object metadata, environmental sensors, external databases) and present processed context data to the access control evaluation module, enabling comprehensive information gathering without directly complicating the core RBAC architecture.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of manufacture

If static permission constraints are used in RBAC, then access control rules are easy to manage, but the system cannot evaluate access dynamically at runtime

Engineering Contradiction:
Improveconstraint managementVSAvoidaccess evaluation responsiveness
Core Design Contradiction:
Ease of manufactureVSProductivity

Solution Approach 1:

The system performs preliminary context information gathering and constraint formulation before access requests are evaluated. Context information is collected and stored in advance, and access constraints are pre-configured with context evaluation rules. When access requests occur, the system quickly evaluates pre-collected context data against pre-formulated constraints, enabling dynamic decision-making without runtime complexity.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8271527B2Refined permission constraints using internal and external data extraction in a role-based access control system
Publication Date: 2012.09.18 ILLINOIS INSTITUTE OF TECHNOLOGY
  • US8271527B2 patent drawing
  • US8271527B2 patent drawing
  • US8271527B2 patent drawing

AI summary

The present invention can enable increasing refinement of role-based permission to access data within a Role Based Access Control (RBAC) controlled computer system by enabling constraints to be written on the role-based permissions. The constraints may utilize each and every type or combination of subject, object, or environment information extracted from sources internal or external to the controlled computer system and may evaluate the content or context of the information extracted to enable refined and dynamic access after the role permission assignment and immediately before every access grant without the reassignment of roles.