Hierarchical Policy Manager for Remote Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Centralized computer systems face challenges in efficiently managing resource allocation and access control for multiple remote users, particularly in maintaining system security and productivity, as failures can lead to significant downtime and administrative complexity.

Innovation Solution

A hierarchical policy manager is implemented to control resource allocation by establishing a policy hierarchy with multiple levels of precedence, allowing administrators to assign priorities and override settings, enabling flexible and efficient access control for remote users.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If centralized resource allocation is implemented to improve system security and resource efficiency, then system security and resource utilization are improved, but administrative complexity and difficulty in managing access control increase

Engineering Contradiction:
Improvesystem securityVSAvoidadministrative complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the policy management system into multiple hierarchical levels (site-level, organizational unit-level, and user-level policies). Each level handles specific aspects of resource allocation and access control, dividing the complex administrative task into manageable segments that can be configured and maintained independently.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces policy templates as intermediary objects that mediate between administrative decisions and actual resource allocation. These templates pre-define access control rules and resource allocation parameters, serving as intermediaries that simplify the translation of administrative intent into system-enforced policies.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If granular access control policies are implemented to improve security, then system security is improved, but device complexity and administrative burden increase

Engineering Contradiction:
Improvesystem securityVSAvoidease of administration
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements policy templates that perform preliminary action by pre-configuring access control rules and resource allocation parameters before they are needed. Administrators can define templates in advance with specific security policies, user groups, and resource assignments, which are then automatically applied when needed, eliminating the need to configure each access control policy from scratch.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses policy templates as reusable copies that can be instantiated multiple times with different parameters. Once a policy template is created and validated, it can be copied and applied to multiple users, groups, or resources, ensuring consistency in security policies while significantly reducing repetitive administrative work.

Inventive Principle:
Principle #26Copying

3Adaptability or versatility

If multiple policy levels with precedence are implemented to improve flexibility in resource allocation, then adaptability and flexibility are improved, but device complexity increases

Engineering Contradiction:
Improveflexibility in resource allocationVSAvoidpolicy management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements a nested hierarchical policy structure where site-level policies contain organizational unit policies, which in turn contain user-level policies. Each level is nested within the previous level and can override or refine policies from parent levels. This nesting allows flexible resource allocation at multiple granularities while maintaining a unified policy framework.

Inventive Principle:
Principle #7Nested doll (Nesting)

Solution Approach 2:

The patent enables local quality by allowing different policy levels to have different priorities and scopes. Site-level policies provide organization-wide defaults, while organizational unit and user-level policies provide localized overrides tailored to specific departments or individuals. This ensures that policies can be customized locally without disrupting the overall system-wide security and resource allocation framework.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS8533775B2Hierarchical policy management
Publication Date: 2013.09.10 MICRO FOCUS LLC
  • US8533775B2 patent drawing
  • US8533775B2 patent drawing
  • US8533775B2 patent drawing

AI summary

A system and method for administering access to a central resource by a remote access device. A system includes a remote access device and a computer executing a hierarchical policy manager. The remote access device requests access to a central resource. The hierarchical policy manager determines a policy for allowing the device to access the resource by evaluating access policies at a plurality of precedence levels of a policy hierarchy. The hierarchical policy manager allows the device to access the resource based on the policy set at the highest precedence level of the policy hierarchy at which access control is specified.