Hierarchical Policy Manager for Remote Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Centralized computer systems face challenges in efficiently managing resource allocation and access control for multiple remote users, particularly in maintaining system security and productivity, as failures can lead to significant downtime and administrative complexity.
Innovation Solution
A hierarchical policy manager is implemented to control resource allocation by establishing a policy hierarchy with multiple levels of precedence, allowing administrators to assign priorities and override settings, enabling flexible and efficient access control for remote users.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If centralized resource allocation is implemented to improve system security and resource efficiency, then system security and resource utilization are improved, but administrative complexity and difficulty in managing access control increase
Solution Approach 1:
The patent segments the policy management system into multiple hierarchical levels (site-level, organizational unit-level, and user-level policies). Each level handles specific aspects of resource allocation and access control, dividing the complex administrative task into manageable segments that can be configured and maintained independently.
Solution Approach 2:
The patent introduces policy templates as intermediary objects that mediate between administrative decisions and actual resource allocation. These templates pre-define access control rules and resource allocation parameters, serving as intermediaries that simplify the translation of administrative intent into system-enforced policies.
2Reliability
If granular access control policies are implemented to improve security, then system security is improved, but device complexity and administrative burden increase
Solution Approach 1:
The patent implements policy templates that perform preliminary action by pre-configuring access control rules and resource allocation parameters before they are needed. Administrators can define templates in advance with specific security policies, user groups, and resource assignments, which are then automatically applied when needed, eliminating the need to configure each access control policy from scratch.
Solution Approach 2:
The patent uses policy templates as reusable copies that can be instantiated multiple times with different parameters. Once a policy template is created and validated, it can be copied and applied to multiple users, groups, or resources, ensuring consistency in security policies while significantly reducing repetitive administrative work.
3Adaptability or versatility
If multiple policy levels with precedence are implemented to improve flexibility in resource allocation, then adaptability and flexibility are improved, but device complexity increases
Solution Approach 1:
The patent implements a nested hierarchical policy structure where site-level policies contain organizational unit policies, which in turn contain user-level policies. Each level is nested within the previous level and can override or refine policies from parent levels. This nesting allows flexible resource allocation at multiple granularities while maintaining a unified policy framework.
Solution Approach 2:
The patent enables local quality by allowing different policy levels to have different priorities and scopes. Site-level policies provide organization-wide defaults, while organizational unit and user-level policies provide localized overrides tailored to specific departments or individuals. This ensures that policies can be customized locally without disrupting the overall system-wide security and resource allocation framework.
Data Source
AI summary
A system and method for administering access to a central resource by a remote access device. A system includes a remote access device and a computer executing a hierarchical policy manager. The remote access device requests access to a central resource. The hierarchical policy manager determines a policy for allowing the device to access the resource by evaluating access policies at a plurality of precedence levels of a policy hierarchy. The hierarchical policy manager allows the device to access the resource based on the policy set at the highest precedence level of the policy hierarchy at which access control is specified.


