Decentralized Folder Access Management for Dynamic Organizations
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current access control technologies in organizations are inefficient and impractical for managing user access rights, particularly in large, complex environments with changing structures and personnel, leading to issues with redundant access rights and orphan accounts, and a lack of effective data security.
Innovation Solution
A decentralized system for managing user data access, where storage elements have ownership attributes, allowing data owners and group owners to control access rights through a folder management application that processes requests and automatically generates proposals based on user behavior, dynamically adapting to organizational changes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If manual review and maintenance of access control lists is used, then data security can be maintained through human oversight, but the system becomes inefficient and inaccurate especially in large organizations with changing structures
Solution Approach 1:
The system enables automatic monitoring of user access behavior and self-adjustment of access rights based on organizational changes. The access control system no longer requires manual intervention but automatically adapts to organizational changes, user behavior patterns, and security policies, thereby maintaining reliability while dramatically improving productivity in large organizations.
2Reliability
If centralized access control management is implemented in IT departments, then security policies can be uniformly enforced, but the system becomes impractical and difficult to manage in complex organizations
Solution Approach 1:
The system segments access control management into autonomous units distributed across different organizational departments and locations. Each segment operates independently with its own access control lists and policies, allowing uniform security enforcement without requiring centralized management. This segmentation reduces system complexity while maintaining security policy consistency across the entire organization.
3Reliability
If traditional access control technologies are used, then basic security can be provided, but redundant access rights and orphan accounts cannot be effectively detected and removed
Solution Approach 1:
The system continuously monitors user access behavior and organizational structure changes, then automatically adjusts access rights based on this feedback. By comparing actual access patterns against assigned permissions and organizational hierarchy, the system detects and eliminates redundant access rights and orphan accounts, preventing information loss while maintaining basic security protection.
4Ease of manufacture
If role-based access control is implemented, then access rights can be standardized according to organizational roles, but the system lacks adaptability to dynamic organizational changes and diverse access control models
Solution Approach 1:
The system dynamically adapts access control configurations to reflect real-time organizational changes while maintaining role-based standardization. As organizational structures, roles, and relationships change, the system automatically updates access rights to match current realities, ensuring both standardization and adaptability in diverse and evolving organizational environments.
Data Source
AI summary
Methods and systems are provided for decentralizing user data access rights control activities in networked organizations having diverse access control models and file server protocols. A folder management application enables end users of the file system to make requests for access to storage elements, either individually, or by becoming members of a user group having group access privileges. Responsibility for dealing with such requests is distributed to respective group owners and data owners, who may delegate responsibility to authorizers. The application may also consider automatically generated proposals for changes to access privileges. An automatic system continually monitors and analyzes access behavior by users who have been pre-classified into groups having common data access privileges. As the organizational structure changes, these groups are adaptively changed both in composition and in data access rights.


