Global Access Control System for Multi-Jurisdictional Compliance

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Bank employees across multiple countries face challenges in sharing information while ensuring appropriate access control, as existing systems fail to comply with varying laws and regulations, leading to insufficient information sharing and potential unauthorized access.

Innovation Solution

A global credit management system that receives a user's login ID, determines their roles and responsibilities, and assesses information accessibility based on the entity managing the information, applicable laws and regulations, and the user's entity affiliation, ensuring access is granted only according to defined roles and compliance with local regulations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If information is managed on a branch-by-branch basis to comply with local laws and regulations, then compliance with national laws is improved, but information sharing among branches deteriorates

Engineering Contradiction:
Improvecompliance with laws and regulationsVSAvoidinformation sharing among branches
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent segments information into multiple classification categories (e.g., public information, confidential information, highly confidential information) based on sensitivity and regulatory requirements. Each category has distinct access control rules that can be applied differently across branches, allowing local compliance while enabling appropriate information sharing. The system divides access control into hierarchical levels that can be configured per branch while maintaining overall system-wide consistency.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements local quality by allowing each branch to have customized access control policies tailored to their specific national laws and regulations, while still participating in the global information sharing system. Different branches can have different classification standards, access permissions, and compliance rules applied locally, yet the system maintains unified management and tracking across all branches.

Inventive Principle:
Principle #3Local quality

2Loss of information

If a unified information sharing system is constructed across all offices, then information sharing is improved, but access control compliance with varying laws deteriorates

Engineering Contradiction:
Improveinformation sharing among officesVSAvoidaccess control compliance
Core Design Contradiction:
Loss of informationVSReliability

Solution Approach 1:

The patent creates a universal information classification framework that can be applied across all branches and offices globally. The core classification categories and access control mechanisms are standardized and reusable across different jurisdictions, enabling consistent information sharing while allowing local customization of specific parameters to meet varying legal requirements.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent implements dynamic access control where permissions and classification levels can be adjusted in real-time based on user roles, request context, and applicable regulations. The system can dynamically modify access rules depending on which branch is accessing which information, allowing a single unified system to adapt to different legal environments without requiring separate systems for each country.

Inventive Principle:
Principle #15Dynamics

3Reliability

If strict access control is implemented to prevent unauthorized access, then security is improved, but ease of operation for legitimate users deteriorates

Engineering Contradiction:
Improveinformation securityVSAvoidaccess to information for employees
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements preliminary action by pre-classifying information into standardized categories and pre-defining access control rules for each classification level. User roles and permissions are pre-configured based on their positions and responsibilities. When users need to access information, the system automatically applies the pre-established rules, eliminating the need for complex real-time authorization decisions and manual security checks.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent enables self-service through automated access control where the system itself determines and enforces access permissions based on pre-configured rules, user profiles, and information classification. The system automatically grants or denies access without requiring manual intervention from security administrators, making the process transparent and efficient for legitimate users while maintaining strict security controls.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10460116B2Access control method, system and storage medium
Publication Date: 2019.10.29 SUMITOMO MITSUI BANKING CORP
  • US10460116B2 patent drawing
  • US10460116B2 patent drawing
  • US10460116B2 patent drawing

AI summary

It is very useful for a bank having offices in a plurality of countries to construct a system that enables bank employees in the offices to share information possessed by the offices. None of conventional systems available to the bank employees in all the offices allow appropriate access control to be performed while complying with laws and regulations that vary among the countries, thus enabling appropriate information to be disclosed to appropriate persons. A system, a method, and a program are provided that allow bank employees in a plurality of countries to access shared information in accordance with the roles & responsibilities of the bank employees while complying with laws and regulations in each country.