Organization-Based Access Control with Boundary Policies

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing policy-based access control systems, such as RBAC and ABAC, face challenges in efficiently managing resource access rights for multi-regional and multi-branded organizations, requiring complex role configurations or attribute rules that are difficult to understand and manage, especially when organizational needs change.

Innovation Solution

An organization-based access control (OBAC) system uses graph data to define resource access rights through team node trees, allowing for hierarchical relationships between teams, automatic generation of access policies, and flexible management of access rights, enabling easy administration and adaptation to changing organizational structures.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If RBAC or ABAC systems are used to manage access rights for multi-regional organizations, then resource access control can be implemented, but the system complexity and difficulty of management increase significantly

Engineering Contradiction:
Improveaccess control effectivenessVSAvoidrole configuration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the organization into hierarchical teams with clear boundaries, where each team is assigned specific resources. This segmentation allows access control to be managed at the team level rather than requiring complex individual role configurations, directly reducing system complexity while maintaining effective access control.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a hierarchical team dimension between users and resources, organizing access control through multiple levels of teams (e.g., regional teams, functional teams). This dimensional approach simplifies management by allowing policies to be defined at each hierarchical level rather than requiring complex cross-cutting role configurations.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Adaptability or versatility

If complex role configurations are created to support multi-regional organizational structures, then access rights can be managed, but the ease of operation and adaptability decrease

Engineering Contradiction:
Improveorganizational structure flexibilityVSAvoidpolicy management ease
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent implements dynamic team hierarchies where teams can be easily created, modified, and dissolved to reflect changing organizational needs. The system automatically adjusts access policies when team structures change, providing both adaptability to organizational evolution and ease of operation through automated policy updates rather than manual reconfiguration.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system enables teams to self-organize and self-manage their own resource access policies within the hierarchical structure. Team leaders can configure resource assignments and access rules for their teams without requiring system administrator intervention, significantly improving ease of operation while maintaining organizational flexibility.

Inventive Principle:
Principle #25Self-service

3Manufacturing precision

If attribute rules are created for each location-specific access requirement, then precise access control can be achieved, but the device complexity and time to manage increase

Engineering Contradiction:
Improveaccess control precisionVSAvoidpolicy configuration time
Core Design Contradiction:
Manufacturing precisionVSLoss of time

Solution Approach 1:

The patent pre-configures hierarchical team structures and assigns resources to teams in advance, establishing access control policies at the team level before specific access requests occur. This preliminary organization eliminates the need to create individual attribute rules for each access scenario, achieving precise location-specific control while dramatically reducing configuration time.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent creates universal team-based access policies that automatically apply to all members of a team regardless of their individual attributes. A single team resource assignment policy serves multiple functions by controlling access for all team members simultaneously, achieving precise location-specific access control without requiring separate attribute rules for each user.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20230421609A1Organization based access control with boundary access policies
Publication Date: 2023.12.28 ORACLE INT CORP
  • US20230421609A1 patent drawing
  • US20230421609A1 patent drawing
  • US20230421609A1 patent drawing

AI summary

An organization-based access control (OBAC) system defines resource access rights using graph-based team node trees, each comprising a plurality of hierarchically-connected team nodes. Each team node is associated with a list of members, team resources, and a team-specific access policy that defines the rights of team members to access the team resources. When a node in a tree has one or more descendant nodes, boundary access policies can be generated to define rights, of members of the node, to access resources associated with descendant nodes. Such boundary access policies may grant parent team members different access rights for child team resources than is granted to the child team members. A node management policy can grant rights to manage a portion of a team node tree. Team-specific access policies, boundary access policies, and management policies can include unique references to one or more particular resources, resource attributes, or groups of resources.