Metadata-Based Access Rights Derivation for Dynamic Document Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional access control list (ACL) solutions are inadequate for metadata-based document management systems, as they are based on static folder structures and do not adapt well to dynamic document management systems where objects' locations vary based on metadata, requiring a more dynamic and flexible approach to access rights management.

Innovation Solution

The solution involves dynamically forming ACLs by deriving access rights from security components originating from metadata items of objects, using pseudo-users, and combining security components to determine effective access rights, which can propagate and be modified automatically based on metadata changes, allowing for flexible and dynamic access control.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If traditional ACL solutions based on static folder structures are used, then access control implementation is straightforward, but they cannot adapt to dynamic document management systems where object locations vary based on metadata

Engineering Contradiction:
Improveadaptability to dynamic document management systemsVSAvoidcomplexity of access control implementation
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent transforms the static ACL model into a dynamic one by deriving access rights from metadata items that can change over time. Instead of fixed folder-based permissions, the system dynamically determines access rights based on current metadata values, allowing the access control structure to adapt automatically as document locations and properties change in the dynamic document management system.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the fundamental parameters of access control from static folder paths to dynamic metadata-based identifiers. By using metadata items (such as document type, author, project, or custom properties) as the basis for deriving access rights, the system allows access control parameters to change dynamically without requiring structural modifications to the ACL implementation itself.

Inventive Principle:
Principle #35Parameter changes

2Adaptability or versatility

If access rights are statically assigned from predefined user groups, then maintenance work is reduced, but the system cannot accommodate dynamic user roles in metadata-based systems

Engineering Contradiction:
Improveflexibility in user role assignmentVSAvoidease of maintenance
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent introduces an intermediary layer between users and access rights through the use of pseudo-users and security components. Instead of directly assigning rights to specific users or groups, the system uses metadata-derived security components that act as intermediaries, automatically resolving which users should have access based on current metadata values. This maintains ease of operation by removing direct user management from the ACL configuration.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system makes user role assignment dynamic by deriving security components from metadata items rather than using static user group definitions. As metadata changes (such as document author, project membership, or classification), the derived access rights automatically update, providing flexibility in user role assignment without requiring manual maintenance of access control lists.

Inventive Principle:
Principle #15Dynamics

3Adaptability or versatility

If ACLs are dynamically formed from metadata items, then adaptability to changing document locations is improved, but the complexity of determining effective access rights increases

Engineering Contradiction:
Improveadaptability to changing document locationsVSAvoidcomplexity of determining effective access rights
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the access control determination process into distinct components: metadata item extraction, security component derivation, and effective access right calculation. By breaking down the complex task of determining access rights into these manageable segments, the system can dynamically adapt to changing document locations while keeping the complexity of each individual segment manageable and reusable.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary actions by pre-defining security components and their derivation rules from metadata items. Rather than calculating effective access rights from scratch for each access request, the system pre-processes metadata to derive security components that can be quickly combined and evaluated, reducing the computational complexity of real-time access determination while maintaining full adaptability.

Inventive Principle:
Principle #10Preliminary action

4Reliability

If multiple security components are combined to determine effective access rights, then comprehensive access control is achieved, but the computational overhead increases

Engineering Contradiction:
Improvecomprehensive access control accuracyVSAvoidaccess right determination speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies partial action by combining security components selectively rather than evaluating all possible metadata-derived components for every access request. The system determines which security components are relevant based on the specific metadata items present and the requested operation, combining only the necessary subset of components to achieve comprehensive access control without the full computational overhead of evaluating every possible security component.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentEP2437199B1A method, an apparatus, a computer system, a security component and a computer readable medium for defining access rights in metadata-based file arrangement
Publication Date: 2017.10.25 M FILES
  • EP2437199B1 patent drawing
  • EP2437199B1 patent drawing
  • EP2437199B1 patent drawing

AI summary

The invention relates to a method for a computer system storing electronic objects being defined by metadata items. The method comprises deriving access rights from one or more security components originating from respective metadata items of at least one object, and determining the effective access rights for the object by means of the security components. The invention also relates to a method for a computer system storing electronic objects being defined by metadata items, wherein access rights for an object are determined by means of one or more pseudo-users. The invention also relates to an apparatus, a computer system and a computer readable medium comprising a computer program stored therein for carrying out the methods.