Hybrid Access Control System for RBAC and ABAC Integration
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Organizations face complexity in managing access control policies, especially when transitioning from role-based access control (RBAC) to attribute-based access control (ABAC), leading to potential disruptions and unintended changes in access permissions.
Innovation Solution
A hybrid access control management system that simultaneously manages both RBAC and ABAC resources, allowing for the gradual integration of attribute-based elements into existing RBAC systems without complete reconfiguration, enabling unified policy creation and enforcement.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If organizations transition from role-based access control (RBAC) to attribute-based access control (ABAC), then access control flexibility and granularity are improved, but system complexity and administrative burden increase
Solution Approach 1:
The patent combines RBAC and ABAC into a hybrid access control system that leverages the strengths of both approaches. RBAC provides structured role-based permissions while ABAC adds attribute-based flexibility, creating a unified system that achieves high adaptability without proportionally increasing complexity.
Solution Approach 2:
The hybrid access control system serves multiple functions simultaneously: it handles traditional role-based access control for standardized scenarios and attribute-based access control for flexible, dynamic scenarios. This multi-functionality allows the system to adapt to various access control needs without requiring separate systems.
2Manufacturing precision
If organizations implement a complete transition to attribute-based access control (ABAC), then fine-grained control over access permissions is improved, but administrative overhead and implementation difficulty increase
Solution Approach 1:
The patent implements ABAC partially within a hybrid system rather than completely replacing RBAC. This partial action approach allows organizations to introduce attribute-based fine-grained control where needed while maintaining the simpler RBAC framework for other scenarios, reducing overall implementation difficulty.
Solution Approach 2:
The hybrid access control system acts as an intermediary layer that translates between RBAC roles and ABAC attributes. This intermediary mechanism enables fine-grained attribute-based control while maintaining compatibility with existing RBAC infrastructure, reducing implementation complexity.
3Reliability
If organizations maintain separate RBAC and ABAC systems, then each system can be optimized independently, but system complexity and management burden increase
Solution Approach 1:
The patent merges RBAC and ABAC into a single hybrid access control system that maintains the optimization benefits of both approaches while统一管理 (unified management) reduces the complexity of managing separate systems. The unified system coordinates role-based and attribute-based access control through integrated policy enforcement.
Data Source
AI summary
Hybrid access control management systems for managing role-based access control resources and attribute-based access control resources are provided. One aspect provides a computing system for implementing hybrid access control management, the computing system comprising: processing circuitry coupled to memory that stores instructions, which, upon execution by the processing circuitry, cause the processing circuitry to: receive a request from a user account to access an access-controlled resource; determine a protection mechanism of the access-controlled resource, wherein the protection mechanism is an attribute-based protection mechanism or a role-based protection mechanism; validate the request from the user account based on the determination of the protection mechanism; and permit the user account to access the access-controlled resource upon successful validation of the request.


