Graph-Based Access Control for Dynamic Permission Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional computing systems used by service providers face challenges in efficiently managing access rights and permissions, particularly in dynamic environments where relationships between users, groups, and resources are complex, leading to inefficiencies and potential misuse due to linear focus and difficulty in keeping up with changing rules and permissions.

Innovation Solution

The implementation of a graph-based access control system that utilizes relationship graphs and a graph database to determine and manage access rights in real-time, allowing for flexible policy-based access control through APIs that integrate with service provider systems, eliminating the need for personally identifiable information and enabling visualization and editing of access rights.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If conventional linear access control systems are used to manage permissions, then implementation is straightforward, but the system cannot effectively handle complex relationships between users, groups, and resources

Engineering Contradiction:
Improveability to handle complex relationshipsVSAvoidsystem structure complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent transitions from linear access control to graph-based access control, adding dimensional complexity to represent relationships. The graph structure with nodes and edges enables multi-dimensional representation of users, groups, and resources, allowing the system to handle complex relationships while maintaining manageable complexity through visual modeling tools.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Reliability

If custom permissions are configured for each user manually, then access control is precise, but significant time and computing resources are required

Engineering Contradiction:
Improveaccess control precisionVSAvoidtime to configure permissions
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system pre-configures graph relationships between users, groups, and resources, so that when access decisions are needed, the graph engine can quickly evaluate pre-established relationships. This preliminary structuring of data enables fast query processing while maintaining precise access control based on the configured relationships.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The graph engine acts as an intermediary between the configured relationships and access decisions. It processes queries by traversing the graph structure to determine access rights, eliminating the need for manual permission configuration for each access scenario while maintaining precision through the established graph relationships.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If traditional access control systems are used, then implementation is simple, but the systems cannot keep up with changing rules and permissions

Engineering Contradiction:
Improveability to update permissionsVSAvoidmanagement system complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The graph-based access control system is inherently dynamic, allowing relationships to be added, removed, or modified in the graph structure. When rules or permissions change, the graph engine automatically re-evaluates access decisions based on the updated graph, enabling the system to adapt to changing requirements without requiring complete reconfiguration.

Inventive Principle:
Principle #15Dynamics

4Adaptability or versatility

If linear permission models are used, then the system is easy to understand, but relationships between different objects and resources are not considered

Engineering Contradiction:
Improverelationship awarenessVSAvoidsystem understandability
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The graph structure serves multiple functions simultaneously: it represents relationships between users, groups, and resources; enables transitive access control; supports inheritance; and provides a visual model for understanding complex permissions. This multi-functionality allows the system to capture relationships while maintaining ease of operation through visual graph interfaces and standardized query mechanisms.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20240414161A1Authorization and access control system for access rights using relationship graphs
Publication Date: 2024.12.12 BREX INC
  • US20240414161A1 patent drawing
  • US20240414161A1 patent drawing
  • US20240414161A1 patent drawing

AI summary

There are provided systems and methods for an authorization and access control system for access rights using relationship graphs. A service provider may provide an authorization and access control system that allows users within the service provider and/or customer entities to assign and change access rights or permissions to computing resources. When providing control of these access rights, the service provider may utilize relationship graphs, queried and generated using a graph database, to visualize and determine access rights that are inherited through different relationships and policies defining these access rights. The relationship graph may show edges for nodes that correspond to related objects, such as actors, groups, and resources. Paths over the relationship graph may be used to determine access rights that may be inherited by users. Once determined, these access rights may be established and/or updated with computing systems.