Hybrid Role Attribute Access Control Policy Simplification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing access control systems become complex and difficult to manage when there are many users and resources, with specific rules required for each user's permissions, leading to inefficiencies in policy maintenance and auditing.

Innovation Solution

A hybrid role and attribute-based access control system that retains all permissions granted to users through roles and modifies them based on user attributes, using a permission-centric approach to simplify policy management and enforcement.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional access control systems are used with many users and resources, then specific rules can be defined for each user's permissions, but the system becomes complex and difficult to manage

Engineering Contradiction:
Improveaccess control precisionVSAvoidpolicy management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments access control policies into hierarchical levels (organization-level, department-level, role-level, and user-level attributes). This segmentation allows complex access control requirements to be broken down into manageable components, reducing overall system complexity while maintaining precise control over user permissions across multiple users and resources.

Inventive Principle:
Principle #1Segmentation

2Reliability

If specific rules are created for each user's permissions, then access control precision is improved, but policy maintenance becomes inefficient

Engineering Contradiction:
Improveaccess control precisionVSAvoidpolicy maintenance efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent merges common access control rules into reusable policy templates that can be applied across multiple users and resources. By combining identical or similar permission requirements into standardized templates, the system maintains precise access control while significantly reducing the time and effort required for policy maintenance, as administrators can update templates once rather than modifying individual user permissions repeatedly.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If traditional access control systems are used, then user permissions can be managed, but auditing becomes burdensome

Engineering Contradiction:
Improveaccess control enforcementVSAvoidauditing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements preliminary action by automatically generating and storing audit trails whenever access control policies are created, modified, or applied. This preliminary documentation of access decisions and policy changes eliminates the need for manual auditing later, as all necessary information is already captured in structured format, significantly reducing auditing time while maintaining comprehensive access control enforcement.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10977380B2Hybrid role and attribute based access control system
Publication Date: 2021.04.13 UPTAKE TECHNOLOGIES INC
  • US10977380B2 patent drawing
  • US10977380B2 patent drawing
  • US10977380B2 patent drawing

AI summary

A method may include receiving, from a client device, a request for a resource of a computer system, determining one or more roles of a user associated with the client device, and determining one or more attributes of the user. The method may include determining one or more attributes of the resource and determining an access permission based on the one or more roles of the user and the resource. The method may include generating, by a processing device, a modified access permission by modifying the access permission based on at least one of: the one or more attributes of the user or the one or more attributes of the resource and providing or denying access to the resource of the computer system based on the modified access permission.