Organization-Based Access Control with Boundary Policies
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing policy-based access control systems, such as RBAC and ABAC, face challenges in efficiently managing resource access rights for multi-regional and multi-branded organizations, requiring complex role configurations or attribute rules that are difficult to understand and manage, especially when organizational needs change.
Innovation Solution
An organization-based access control (OBAC) system uses graph data to define resource access rights through team node trees, allowing for hierarchical relationships between teams, automatic generation of access policies, and flexible management of access rights, enabling easy administration and adaptation to changing organizational structures.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If RBAC or ABAC systems are used to manage access rights for multi-regional organizations, then resource access control can be implemented, but the system complexity and difficulty of management increase significantly
Solution Approach 1:
The patent segments the organization into hierarchical teams with clear boundaries, where each team is assigned specific resources. This segmentation allows access control to be managed at the team level rather than requiring complex individual role configurations, directly reducing system complexity while maintaining effective access control.
Solution Approach 2:
The patent introduces a hierarchical team dimension between users and resources, organizing access control through multiple levels of teams (e.g., regional teams, functional teams). This dimensional approach simplifies management by allowing policies to be defined at each hierarchical level rather than requiring complex cross-cutting role configurations.
2Adaptability or versatility
If complex role configurations are created to support multi-regional organizational structures, then access rights can be managed, but the ease of operation and adaptability decrease
Solution Approach 1:
The patent implements dynamic team hierarchies where teams can be easily created, modified, and dissolved to reflect changing organizational needs. The system automatically adjusts access policies when team structures change, providing both adaptability to organizational evolution and ease of operation through automated policy updates rather than manual reconfiguration.
Solution Approach 2:
The system enables teams to self-organize and self-manage their own resource access policies within the hierarchical structure. Team leaders can configure resource assignments and access rules for their teams without requiring system administrator intervention, significantly improving ease of operation while maintaining organizational flexibility.
3Manufacturing precision
If attribute rules are created for each location-specific access requirement, then precise access control can be achieved, but the device complexity and time to manage increase
Solution Approach 1:
The patent pre-configures hierarchical team structures and assigns resources to teams in advance, establishing access control policies at the team level before specific access requests occur. This preliminary organization eliminates the need to create individual attribute rules for each access scenario, achieving precise location-specific control while dramatically reducing configuration time.
Solution Approach 2:
The patent creates universal team-based access policies that automatically apply to all members of a team regardless of their individual attributes. A single team resource assignment policy serves multiple functions by controlling access for all team members simultaneously, achieving precise location-specific access control without requiring separate attribute rules for each user.
Data Source
AI summary
An organization-based access control (OBAC) system defines resource access rights using graph-based team node trees, each comprising a plurality of hierarchically-connected team nodes. Each team node is associated with a list of members, team resources, and a team-specific access policy that defines the rights of team members to access the team resources. When a node in a tree has one or more descendant nodes, boundary access policies can be generated to define rights, of members of the node, to access resources associated with descendant nodes. Such boundary access policies may grant parent team members different access rights for child team resources than is granted to the child team members. A node management policy can grant rights to manage a portion of a team node tree. Team-specific access policies, boundary access policies, and management policies can include unique references to one or more particular resources, resource attributes, or groups of resources.


