Modular Information Sharing Platform Using ICAM and ABAC

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing computer portals are expensive to maintain and difficult to upgrade, with complex registration processes, siloed information, inconsistent user interfaces, and administrative burdens, making it hard for users to access services and for community leaders to manage access effectively.

Innovation Solution

A modular information sharing platform that uses an Identity, Credential, and Access Management (ICAM) component and Attribute-Based Access Control (ABAC) to authenticate users and customize content access, enabling seamless access to services while preventing unauthorized access through a secure and intuitive user interface.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a monolithic application structure is used to provide comprehensive services, then all services can be accessed through a single portal, but the system becomes expensive to maintain and difficult to upgrade

Engineering Contradiction:
Improveservice accessibilityVSAvoidsystem maintenance complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent divides the monolithic application into separate, modular components that can be independently developed, maintained, and upgraded. Each component serves a specific function, allowing the system to maintain comprehensive service accessibility while reducing overall maintenance complexity through modular architecture.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates a universal access layer that provides consistent interface to multiple underlying components. This allows a single portal to access diverse services through standardized mechanisms, maintaining versatility while enabling independent component management.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If a monolithic application structure is used to provide comprehensive services, then all services can be accessed through a single portal, but the system becomes difficult to upgrade

Engineering Contradiction:
Improveservice accessibilityVSAvoidsystem upgradeability
Core Design Contradiction:
Adaptability or versatilityVSEase of manufacture

Solution Approach 1:

By segmenting the system into independent components with defined interfaces, the patent enables targeted upgrades of specific services without requiring system-wide changes. Each component can be upgraded independently while maintaining overall system functionality.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent extracts individual service components from the monolithic structure, allowing them to be developed, tested, and deployed independently. This extraction enables continuous integration and deployment practices that simplify the upgrade process.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If content is made available only to group members, then community information security is improved, but user access and information discovery become difficult

Engineering Contradiction:
Improveinformation securityVSAvoiduser access ease
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces an intermediary access layer that manages authentication and authorization between users and protected content. This intermediary enables secure access control while providing a user-friendly interface that automatically handles security checks, making the process transparent to users.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements feedback mechanisms that provide users with clear information about their access status and permissions. Users receive feedback on whether they can access specific content and what actions are available to them, improving ease of operation while maintaining security.

Inventive Principle:
Principle #23Feedback

4Reliability

If a two-step authorization process is implemented, then access control security is improved, but user login complexity increases

Engineering Contradiction:
Improveaccess control securityVSAvoidlogin process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges multiple authorization checks into a unified authentication process. By combining identity verification with access rights determination in a single integrated flow, the system maintains strong security controls while reducing the perceived complexity for users.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

An intermediary authentication service handles the complex two-step authorization process behind the scenes, presenting a simplified interface to users. This mediator manages the security complexity internally while providing a streamlined user experience.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20250023865A1Computer system architecture with modular approach
Publication Date: 2025.01.16 THE GOVERNMENT OF THE UNITED STATES OF AMERICA AS REPRESENTED BY THE SEC OF HOMELAND SECURITY
  • US20250023865A1 patent drawing
  • US20250023865A1 patent drawing
  • US20250023865A1 patent drawing

AI summary

Embodiments include a method to provide access to services, including receiving, by an information sharing platform, a user at a landing page of the information sharing platform for selectively accessing services through the information sharing platform. The information sharing platform can use an application programming interface (API) to access an Identity, Credential, and Access Management (ICAM) component to authenticate the user based on user credentials of the user. The information sharing platform stores and retrieves profile attributes for the user, which is uses to customize the information sharing platform content presented to the user. The information sharing platform retrieves, from the ICAM component, Attribute-Based Access Control (ABAC) credentials corresponding to the ICAM component authenticating the user, and selectively enables or prevents access (based on the ABAC credentials) to components that provide component services, or content which the information sharing platform fetches and retrieves from components.