Ontology-Based Access Control for Dynamic Policy Adaptation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing access control systems, particularly those based on the Role-Based Access Control (RBAC) model, are rigid and require heavy manual intervention to update access control policies, leading to slow adaptation to dynamic changes and increased management costs due to the need for multiple experts to interpret and validate complex, unstructured policies.

Innovation Solution

Implementing an access control system that utilizes an ontology to store and manage access control knowledge, allowing for dynamic updates and queries based on a formalized access control ontology, reducing manual intervention and improving accuracy through automated reasoning and inference engines.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If access control policies are defined in unstructured natural language to allow dynamic changes, then adaptability is improved, but manual intervention and complexity increase

Engineering Contradiction:
ImproveadaptabilityVSAvoidcomplexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary component (access control policy translator/interpreter) that bridges unstructured natural language policies and structured access control rules. This intermediary automatically translates dynamic natural language policies into machine-executable RBAC rules, maintaining adaptability while reducing manual intervention complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system enables self-service by allowing access control policies to be updated through natural language definitions without requiring manual intervention from security experts. The automated translation and validation mechanisms handle policy updates autonomously, improving adaptability while reducing operational complexity.

Inventive Principle:
Principle #25Self-service

2Reliability

If manual interpretation and validation of access control policies is performed by multiple experts, then reliability is improved, but productivity and speed are worsened

Engineering Contradiction:
ImprovereliabilityVSAvoidproductivity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent replaces the mechanical process of manual interpretation and validation by multiple experts with an automated computational system. The system uses algorithmic translation and validation mechanisms to process access control policies, significantly improving productivity while maintaining reliability through systematic error checking and validation rules.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system implements feedback mechanisms where the automated translation and validation process provides immediate verification of policy correctness. Error detection and correction feedback loops ensure reliability without requiring multiple manual review cycles, thereby improving productivity.

Inventive Principle:
Principle #23Feedback

3Adaptability or versatility

If access control rules are updated frequently to match dynamic policies, then adaptability is improved, but the rigid RBAC model and manual processes cause delays

Engineering Contradiction:
ImproveadaptabilityVSAvoidspeed
Core Design Contradiction:
Adaptability or versatilityVSSpeed

Solution Approach 1:

The patent transforms the static RBAC model into a dynamic system by implementing automated policy translation and update mechanisms. The system can rapidly adapt to changing access control requirements by automatically translating new natural language policies into updated RBAC rules, improving both adaptability and speed of policy implementation.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system performs preliminary actions by pre-compiling and validating access control rules in advance. When policy changes are needed, the automated translation mechanism can quickly generate updated rules based on pre-established templates and validation patterns, reducing the time required for policy updates.

Inventive Principle:
Principle #10Preliminary action

4Manufacturing precision

If heavy manual intervention is used to update access control policies, then accuracy is improved, but loss of time and productivity are worsened

Engineering Contradiction:
ImproveaccuracyVSAvoidtime
Core Design Contradiction:
Manufacturing precisionVSLoss of time

Solution Approach 1:

The patent replaces manual interpretation and validation mechanics with automated computational processes. The system uses algorithmic translation from natural language to RBAC rules with built-in validation logic, achieving high accuracy in policy implementation while dramatically reducing the time required for policy updates compared to manual processes.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS11399030B2Ontology based control of access to resources in a computing system
Publication Date: 2022.07.26 KYNDRYL INC
  • US11399030B2 patent drawing
  • US11399030B2 patent drawing
  • US11399030B2 patent drawing

AI summary

A solution is proposed for controlling access to one or more resources of a computing system. A corresponding method comprises storing a knowledge base, which provides a knowledge of an access control to the resources in conformity with an access control ontology. In response to an update request, the access control ontology is updated according to update assertions obtained from the update request. In response to an access request (for a selected access to a selected resource), the selected access is granted or denied according to a result of an access query (for querying the access control ontology) obtained from the access request. A computer program and a computer program product for performing the method are also proposed. Moreover, a corresponding system (particularly, a control computing machine) is proposed.