Network Model Access Control Granularity Adaptability

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional security and access control methods in software applications are inflexible and brittle, struggling to adapt to frequent changes in application architecture, as they often require updating access policies for new components and resources, and lack deep integration with business information models, leading to cumbersome management and limited access control granularity.

Innovation Solution

A method and system for providing security and access control using a multi-dimensional network model with nodes representing entities like goals, tasks, responsibilities, and roles, allowing for dynamic and intuitive policy creation and modification through a node-based interface, enabling granular access control and scoping rules that are integral to the business model.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Manufacturing precision

If access control is implemented at the resource level (database tables, rows, screens, APIs), then security granularity is improved, but adaptability to architectural changes deteriorates

Engineering Contradiction:
Improveaccess control granularityVSAvoidadaptability to architectural changes
Core Design Contradiction:
Manufacturing precisionVSAdaptability or versatility

Solution Approach 1:

The patent introduces a new dimension - the task level - between the resource level and the user level. Instead of directly controlling access to individual resources (database tables, screens, APIs), the system controls access at the task level, which then automatically manages the underlying resource access. This dimensional shift allows coarse-grained task-level policies to control fine-grained resource access without requiring policy updates when resources change, thus resolving the contradiction between granularity and adaptability.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Reliability

If access control policies are updated to include new screens and resources, then security coverage is improved, but ease of operation deteriorates

Engineering Contradiction:
Improvesecurity coverageVSAvoidease of policy management
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system implements self-service by automatically generating and updating access control policies based on task definitions and user-task assignments. When new resources are added to existing tasks, the system automatically extends access control coverage to these resources without requiring manual policy updates. The task-level abstraction enables the system to self-adapt to architectural changes, maintaining comprehensive security coverage while eliminating the operational burden of manual policy management.

Inventive Principle:
Principle #25Self-service

3Ease of operation

If role-driven access control is implemented, then ease of operation is improved, but adaptability to complex business relationships deteriorates

Engineering Contradiction:
Improveease of access control managementVSAvoidintegration with business information models
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The patent merges role-driven access control with task-driven access control into a unified framework. Users are assigned to tasks, and tasks are associated with roles, combining the simplicity of role-based assignment with the flexibility of task-based security policies. This integration allows the system to maintain ease of operation through role assignments while simultaneously achieving adaptability to complex business relationships through task-level policy definitions that can incorporate complex business logic and relationships.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS12184699B2Method and a system for providing security and access control in a network model
Publication Date: 2024.12.31 PRAMA INC
  • US12184699B2 patent drawing
  • US12184699B2 patent drawing
  • US12184699B2 patent drawing

AI summary

The invention relates to method and system for providing security and access control in a network model. The method includes generating a network model including process entities. Each of the process entities is represented by a corresponding node on a node-based User-Interface. Each of nodes corresponding to the entities is configured to be linked with at least one of remaining nodes of the nodes in the node-based User-Interface, via an interconnection network link. The method further includes receiving one or more attributes associated with each of the nodes; and creating an access control policy for a target node of the nodes. Accessing the target node includes at least one of view the attributes associated with the target node; modifying the attributes associated with the target node; or modifying an interconnection network link between the target node and another node of the nodes.