Metadata-Based Access Rights Derivation for Dynamic Document Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional access control list (ACL) solutions are inadequate for metadata-based document management systems, as they are based on static folder structures and do not adapt well to dynamic document management systems where objects' locations vary based on metadata, requiring a more dynamic and flexible approach to access rights management.
Innovation Solution
The solution involves dynamically forming ACLs by deriving access rights from security components originating from metadata items of objects, using pseudo-users, and combining security components to determine effective access rights, which can propagate and be modified automatically based on metadata changes, allowing for flexible and dynamic access control.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If traditional ACL solutions based on static folder structures are used, then access control implementation is straightforward, but they cannot adapt to dynamic document management systems where object locations vary based on metadata
Solution Approach 1:
The patent transforms the static ACL model into a dynamic one by deriving access rights from metadata items that can change over time. Instead of fixed folder-based permissions, the system dynamically determines access rights based on current metadata values, allowing the access control structure to adapt automatically as document locations and properties change in the dynamic document management system.
Solution Approach 2:
The patent changes the fundamental parameters of access control from static folder paths to dynamic metadata-based identifiers. By using metadata items (such as document type, author, project, or custom properties) as the basis for deriving access rights, the system allows access control parameters to change dynamically without requiring structural modifications to the ACL implementation itself.
2Adaptability or versatility
If access rights are statically assigned from predefined user groups, then maintenance work is reduced, but the system cannot accommodate dynamic user roles in metadata-based systems
Solution Approach 1:
The patent introduces an intermediary layer between users and access rights through the use of pseudo-users and security components. Instead of directly assigning rights to specific users or groups, the system uses metadata-derived security components that act as intermediaries, automatically resolving which users should have access based on current metadata values. This maintains ease of operation by removing direct user management from the ACL configuration.
Solution Approach 2:
The system makes user role assignment dynamic by deriving security components from metadata items rather than using static user group definitions. As metadata changes (such as document author, project membership, or classification), the derived access rights automatically update, providing flexibility in user role assignment without requiring manual maintenance of access control lists.
3Adaptability or versatility
If ACLs are dynamically formed from metadata items, then adaptability to changing document locations is improved, but the complexity of determining effective access rights increases
Solution Approach 1:
The patent segments the access control determination process into distinct components: metadata item extraction, security component derivation, and effective access right calculation. By breaking down the complex task of determining access rights into these manageable segments, the system can dynamically adapt to changing document locations while keeping the complexity of each individual segment manageable and reusable.
Solution Approach 2:
The system performs preliminary actions by pre-defining security components and their derivation rules from metadata items. Rather than calculating effective access rights from scratch for each access request, the system pre-processes metadata to derive security components that can be quickly combined and evaluated, reducing the computational complexity of real-time access determination while maintaining full adaptability.
4Reliability
If multiple security components are combined to determine effective access rights, then comprehensive access control is achieved, but the computational overhead increases
Solution Approach 1:
The patent applies partial action by combining security components selectively rather than evaluating all possible metadata-derived components for every access request. The system determines which security components are relevant based on the specific metadata items present and the requested operation, combining only the necessary subset of components to achieve comprehensive access control without the full computational overhead of evaluating every possible security component.
Data Source
AI summary
The invention relates to a method for a computer system storing electronic objects being defined by metadata items. The method comprises deriving access rights from one or more security components originating from respective metadata items of at least one object, and determining the effective access rights for the object by means of the security components. The invention also relates to a method for a computer system storing electronic objects being defined by metadata items, wherein access rights for an object are determined by means of one or more pseudo-users. The invention also relates to an apparatus, a computer system and a computer readable medium comprising a computer program stored therein for carrying out the methods.


