Hybrid Access Control System for RBAC and ABAC Integration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Organizations face complexity in managing access control policies, especially when transitioning from role-based access control (RBAC) to attribute-based access control (ABAC), leading to potential disruptions and unintended changes in access permissions.

Innovation Solution

A hybrid access control management system that simultaneously manages both RBAC and ABAC resources, allowing for the gradual integration of attribute-based elements into existing RBAC systems without complete reconfiguration, enabling unified policy creation and enforcement.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If organizations transition from role-based access control (RBAC) to attribute-based access control (ABAC), then access control flexibility and granularity are improved, but system complexity and administrative burden increase

Engineering Contradiction:
Improveaccess control flexibilityVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent combines RBAC and ABAC into a hybrid access control system that leverages the strengths of both approaches. RBAC provides structured role-based permissions while ABAC adds attribute-based flexibility, creating a unified system that achieves high adaptability without proportionally increasing complexity.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The hybrid access control system serves multiple functions simultaneously: it handles traditional role-based access control for standardized scenarios and attribute-based access control for flexible, dynamic scenarios. This multi-functionality allows the system to adapt to various access control needs without requiring separate systems.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Manufacturing precision

If organizations implement a complete transition to attribute-based access control (ABAC), then fine-grained control over access permissions is improved, but administrative overhead and implementation difficulty increase

Engineering Contradiction:
Improveaccess permission granularityVSAvoidimplementation difficulty
Core Design Contradiction:
Manufacturing precisionVSEase of manufacture

Solution Approach 1:

The patent implements ABAC partially within a hybrid system rather than completely replacing RBAC. This partial action approach allows organizations to introduce attribute-based fine-grained control where needed while maintaining the simpler RBAC framework for other scenarios, reducing overall implementation difficulty.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The hybrid access control system acts as an intermediary layer that translates between RBAC roles and ABAC attributes. This intermediary mechanism enables fine-grained attribute-based control while maintaining compatibility with existing RBAC infrastructure, reducing implementation complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If organizations maintain separate RBAC and ABAC systems, then each system can be optimized independently, but system complexity and management burden increase

Engineering Contradiction:
Improvesystem optimizationVSAvoidmanagement burden
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges RBAC and ABAC into a single hybrid access control system that maintains the optimization benefits of both approaches while统一管理 (unified management) reduces the complexity of managing separate systems. The unified system coordinates role-based and attribute-based access control through integrated policy enforcement.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS20250103734A1Hybrid access control resource management
Publication Date: 2025.03.27 MICROSOFT TECHNOLOGY LICENSING LLC
  • US20250103734A1 patent drawing
  • US20250103734A1 patent drawing
  • US20250103734A1 patent drawing

AI summary

Hybrid access control management systems for managing role-based access control resources and attribute-based access control resources are provided. One aspect provides a computing system for implementing hybrid access control management, the computing system comprising: processing circuitry coupled to memory that stores instructions, which, upon execution by the processing circuitry, cause the processing circuitry to: receive a request from a user account to access an access-controlled resource; determine a protection mechanism of the access-controlled resource, wherein the protection mechanism is an attribute-based protection mechanism or a role-based protection mechanism; validate the request from the user account based on the determination of the protection mechanism; and permit the user account to access the access-controlled resource upon successful validation of the request.