Policy-Based Access Control System for Ethical Walls

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current access control systems, such as Unix permissions and access control lists, lack flexibility and universality, failing to effectively manage access to information across different file systems, applications, and organizations, particularly in preventing unauthorized access and ensuring compliance with regulations like the Sarbanes-Oxley Act.

Innovation Solution

A policy-based information management system with a centralized policy server that enforces rules across an organization, allowing granular control over access to documents, emails, and applications, ensuring separation of duties and compliance by evaluating user requests against predefined policies stored on user devices or servers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If Unix permissions or access control lists are used to manage access, then access control functionality is provided, but flexibility and universality across different file systems, applications, and organizations are limited

Engineering Contradiction:
Improveaccess control flexibilityVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements a universal access control system that operates across multiple file systems, applications, and organizational boundaries. The system uses a standardized policy framework that can be applied uniformly to different types of information resources (files, emails, applications) and different user groups, enabling consistent access control semantics throughout the enterprise infrastructure without requiring separate control mechanisms for each resource type.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent introduces an intermediary access control system that sits between users and information resources. This intermediary layer translates high-level organizational policies into specific access decisions for individual resources. The system mediates access requests by evaluating user attributes, resource attributes, and organizational policies, thereby simplifying the complexity of direct resource-by-resource control while maintaining comprehensive access management capability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If traditional access control systems are used, then basic permission management is achieved, but the ability to prevent unauthorized access and ensure compliance with regulations is insufficient

Engineering Contradiction:
Improveaccess control effectivenessVSAvoidpolicy management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements preliminary action by establishing comprehensive access control policies and user attribute definitions before access requests occur. The system pre-configures organizational policies that define acceptable access patterns, user roles, and resource classifications. When access requests are made, the system simply evaluates these pre-established policies rather than making ad-hoc decisions, thereby ensuring consistent and reliable access control while reducing the complexity of real-time policy management.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent incorporates feedback mechanisms that monitor access decisions and enforce compliance with organizational policies. The system tracks access patterns, evaluates policy violations, and provides feedback for policy refinement. This feedback loop ensures that the access control system adapts to emerging security requirements while maintaining reliable enforcement of compliance standards, and reduces management complexity by automatically identifying and reporting policy issues.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10380363B2Preventing conflicts of interests between two or more groups using applications
Publication Date: 2019.08.13 NEXTLABS INC
  • US10380363B2 patent drawing
  • US10380363B2 patent drawing
  • US10380363B2 patent drawing

AI summary

To prevent conflicts of interest, an information management system is used to make sure two or more groups are kept apart so that information does not circulate freely between these groups. The system has policies to implement an “ethical wall” to separate users or groups of users. The user or groups of user may be organized in any arbitrary way, and may be in the same organization or different organizations. The two groups (or two or more users) will not be able to access information belonging to the other, and users in one group may not be able to pass information to the other group. The system may manage access to documents, e-mail, files, and other forms of information.