Link-Embedded Access Control Identifiers for Dynamic Enterprise Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Enterprises face challenges in controlling access to sensitive information, including restricting access to a limited set of users, revoking access when user roles change, and applying access control changes due to outdated security policies, often leading to security vulnerabilities and inefficiencies.

Innovation Solution

Embedding a resource access identifier, such as a random cryptographic token, in a link to a shared computing resource and associating it with a digital rights management (DRM) profile, allowing secure access control by embedding the identifier and DRM profile in information elements like emails or files, enabling only authorized devices to access the resource.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If access lists are updated frequently to maintain security, then security reliability is improved, but loss of time and administrative overhead increase

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidtime for updating access lists
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent extracts the access control identifier from the resource itself and embeds it directly into the link. This separation allows the link to carry its own authentication credentials, eliminating the need for centralized access list management and reducing administrative overhead while maintaining security.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The link becomes self-sufficient by containing the access control identifier within its structure. The link can independently verify access rights without requiring external access list queries, enabling self-service authentication that reduces time-consuming administrative updates.

Inventive Principle:
Principle #25Self-service

2Loss of time

If resource owners list more users in access lists to avoid frequent updates, then administrative time is reduced, but security vulnerabilities increase

Engineering Contradiction:
Improvetime for updating access listsVSAvoidsecurity vulnerabilities
Core Design Contradiction:
Loss of timeVSObject-affected harmful factors

Solution Approach 1:

The patent applies local quality by making each link individually authenticated with its own embedded access control identifier. Instead of relying on global access list policies that may be overly permissive, each link has localized security credentials that precisely control access on a per-link basis, eliminating security vulnerabilities from over-granting access.

Inventive Principle:
Principle #3Local quality

3Reliability

If IT professionals manage access lists, then technical implementation is ensured, but business process efficiency decreases

Engineering Contradiction:
Improvetechnical implementation reliabilityVSAvoidbusiness process efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system enables business professionals to self-service access control by automatically generating links with embedded access control identifiers. This eliminates the need for IT professional intervention in routine access granting, significantly improving business process efficiency while maintaining technical reliability through automated security protocols.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent introduces an intermediary mechanism (the embedded access control identifier in the link) that bridges the gap between business users needing access and IT security requirements. This intermediary enables direct access control without IT involvement, improving efficiency while preserving security through structured identifier validation.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Device complexity

If traditional access control methods are used, then centralized management is maintained, but adaptability to changing user roles decreases

Engineering Contradiction:
Improvecentralized management structureVSAvoidadaptability to user role changes
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamics by making access control identifiers embedded in links dynamically generable and modifiable. When user roles change, new links with updated identifiers can be generated instantly without restructuring centralized access lists, providing high adaptability to changing business requirements while maintaining manageable complexity through standardized identifier formats.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentEP2404258B1Access control using identifiers in links
Publication Date: 2016.11.23 MICROSOFT TECHNOLOGY LICENSING LLC
  • EP2404258B1 patent drawingFigure 1
  • EP2404258B1 patent drawingFigure 2
  • EP2404258B1 patent drawingFigure 3

AI summary

Methods, systems, and computer-readable media are disclosed for access control. A particular method receives a resource access identifier associated with a shared computing resource and embeds the resource access identifier into a link to the shared resource. The link to the shared resource is inserted into an information element. An access control scheme is associated with the information element to generate a protected information element, and the protected information element is sent to a destination computing device.