Federated Area Inheritance for Secure Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increasing complexity and volume of data in scientific and technical applications necessitate improved mechanisms for organizing and overseeing the development of task routines and analysis tasks, particularly in distributed environments, to ensure reproducibility, accountability, and efficient reuse of data and components.

Innovation Solution

A system utilizing a network-based portal to manage federated areas, where multiple objects including data sets, job flow definitions, task routines, and result reports are stored, allowing controlled access and transfer between remote devices, with a hierarchical structure and security credentials to govern access and inheritance relationships.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If data and task routines are pooled in federated areas to enable collaboration and reuse, then productivity and adaptability improve, but device complexity and security management become more difficult

Engineering Contradiction:
Improvecollaboration efficiencyVSAvoidaccess control complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The system segments federated areas into private and shared components, with distinct access control mechanisms for each. Private federated areas use inheritance relationships where child areas automatically receive permissions from parent areas, while shared areas have explicit access grants. This segmentation resolves the contradiction by organizing complexity hierarchically rather than flatly.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary access control system that mediates between remote devices and federated areas. The system uses security credentials, inheritance relationships, and explicit access grants as intermediaries to manage permissions automatically, reducing the manual complexity of access control while maintaining security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If access control mechanisms are implemented to ensure security and accountability, then reliability improves, but ease of operation deteriorates

Engineering Contradiction:
Improveaccess control securityVSAvoidsystem usability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system performs preliminary actions by pre-establishing inheritance relationships between parent and child federated areas. When a child area is created, it automatically inherits access permissions from its parent, eliminating the need for manual permission configuration. This preliminary setup maintains security while simplifying subsequent operations.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The access control system enables self-service through automatic inheritance propagation. When permissions are granted to a parent federated area, the system automatically propagates these permissions to child areas without requiring manual intervention. This self-service mechanism maintains reliability while improving ease of operation.

Inventive Principle:
Principle #25Self-service

3Adaptability or versatility

If hierarchical inheritance relationships are established between federated areas, then adaptability and reuse improve, but device complexity increases

Engineering Contradiction:
Improvefederated area flexibilityVSAvoidhierarchy management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements a nested hierarchical structure where child federated areas are nested within parent areas. This nesting enables automatic inheritance of access permissions and task routines through multiple hierarchical levels. The nested structure provides adaptability through flexible hierarchy creation while the system automatically manages the complexity of permission propagation.

Inventive Principle:
Principle #7Nested doll (Nesting)

Data Source

PatentUS10095554B2Automated generation of private federated areas
Publication Date: 2018.10.09 SAS INSTITUTE INC
  • US10095554B2 patent drawing
  • US10095554B2 patent drawing
  • US10095554B2 patent drawing

AI summary

An apparatus includes a processor to: receive a request from a first remote device to provide a second remote device with access to an existing federated area; allocate storage for a new private federated accessible to the second remote device and not to the first remote device; maintain an inheritance relationship between the existing and new private federated areas in which an object stored in the existing federated area is made accessible to the second remote device to the same extent as an object in the new private federated area; and maintain a priority relationship between the existing and new private federated areas as an exception to the inheritance relationship such that priority is given to providing the second remote device with access to a task routine stored in the new private federated area over a task routine stored in the existing federated area that performs the same task.