Entity-Generic Records for Unified Asset Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Managing access to assets across multiple entities is inefficient due to differences in user and asset record terminology and attributes, leading to increased customer service costs, delays, and security workarounds.

Innovation Solution

Creating entity-generic user and asset records by analyzing entity-specific records to align user entitlements and asset permissions in a unified system, allowing for streamlined access determination and insight into entitlement and permission information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If entity-specific user records and asset records are managed separately with different terminology and attributes, then each entity can maintain its own access control policies, but determining access rights becomes time-consuming and resource-intensive

Engineering Contradiction:
Improveability to maintain entity-specific access control policiesVSAvoidtime to determine access rights
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The patent creates a universal entity-generic record structure that can represent users and assets from multiple different entities using a common schema. This generic structure serves multiple functions: it preserves entity-specific attributes through mapping, enables cross-entity access determination, and provides a unified view for access control decisions. The entity-generic user records and asset records use standardized attributes (entitlements and permissions) that work across all entities, eliminating the need to handle each entity's unique terminology separately.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The entity-generic records act as an intermediary layer between entity-specific records and the access determination process. Instead of directly comparing disparate entity-specific records, the system translates them into a common entity-generic format that includes standardized entitlements and permissions. This intermediary representation enables efficient access determination by providing a unified language for comparing user rights against asset requirements, while still preserving the original entity-specific information when needed.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If customer service representatives manually determine access rights using entity-specific records, then access control decisions can be customized for each entity, but service costs and resource consumption increase

Engineering Contradiction:
Improvecustomization of access control decisionsVSAvoidservice costs and resource consumption
Core Design Contradiction:
Adaptability or versatilityVSLoss of energy

Solution Approach 1:

The system enables automated self-service access determination by comparing entity-generic user record entitlements with entity-generic asset record permissions. The access control decision-making process is transformed from a manual, representative-driven task into an automated system that independently evaluates whether a user's entitlements satisfy an asset's permission requirements. This automation eliminates the need for customer service representatives to manually investigate access rights, significantly reducing service costs and resource consumption while maintaining customized access control through the preserved entity-specific attributes.

Inventive Principle:
Principle #25Self-service

3Productivity

If a unified access control system is implemented across multiple entities, then access determination becomes more efficient, but differences in user and asset record structures must be reconciled

Engineering Contradiction:
Improveaccess determination efficiencyVSAvoidcomplexity of reconciling record structures
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent segments the access control system into distinct layers: entity-specific record structures are separated from the unified access determination logic through the introduction of entity-generic records. Each entity's specific attributes and terminology are preserved in their original records, while a standardized generic layer handles cross-entity comparisons. This segmentation allows the system to maintain high productivity through automated unified processing while managing complexity by isolating entity-specific variations into separate, manageable segments that don't interfere with each other.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS9231956B1Utilizing entity-generic records for determining access to assets
Publication Date: 2016.01.05 EMC IP HLDG CO LLC
  • US9231956B1 patent drawing
  • US9231956B1 patent drawing
  • US9231956B1 patent drawing

AI summary

A method comprises the following steps. Entity-generic user records are created for a plurality of users associated with a plurality of entities by analyzing entity-specific user records for the plurality of users, wherein the entity-generic user records comprise respective sets of entitlements for the plurality of users. Entity-generic asset records for assets associated with the plurality of entities are created by analyzing entity-specific asset records for the plurality of assets, wherein the entity-generic asset records comprise respective sets of permissions for accessing the plurality of assets. An entity-generic user record for a given user is utilized to determine whether the given user has access to a given asset by comparing the set of entitlements in the given entity-generic user record with the set of permissions in an entity-generic asset record for the given asset.