Policy Control Engine for Hierarchical Workspace Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current shared online workspace environments struggle to enforce hierarchical collaboration policies across different administrative entities, leading to inconsistencies and lack of control over access and activities, particularly when guests from one entity interact with resources governed by another entity's policies.
Innovation Solution
Implementing a policy control engine that applies the stricter policies of participating entities to ensure seamless coexistence of individual policies within a shared resource, allowing each administrative entity to manage access and activities according to their defined rules.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a guest account system is used to allow external clients to access the workspace, then collaboration with outside entities is enabled, but the external clients' own policies are not enforced and they are governed only by the administrative entity's policies
Solution Approach 1:
The patent introduces a policy enforcement point (PEP) as an intermediary component that sits between external clients and the workspace resources. This PEP acts as a mediator that receives policy decisions from the external client's administrative entity and enforces them within the workspace environment, thereby enabling policy enforcement for guest accounts without preventing collaboration.
Solution Approach 2:
The patent segments the policy enforcement mechanism into separate components: a policy decision point (PDP) that determines which policies apply, and a policy enforcement point (PEP) that actually implements the policies. This segmentation allows the system to handle multiple administrative entities' policies independently and enforce them appropriately for each external client.
2Reliability
If hierarchical collaboration policies are implemented to enforce multiple administrative entities' policies, then policy control and security are improved, but system complexity increases due to the need to manage and reconcile multiple policy sets
Solution Approach 1:
The policy enforcement point serves as an intermediary that simplifies the complexity by providing a standardized interface for policy enforcement. Instead of requiring the workspace system to directly manage and reconcile multiple complex policy sets from different administrative entities, the PEP handles this complexity internally while presenting a unified enforcement mechanism to the workspace.
Solution Approach 2:
The system implements feedback mechanisms where the policy enforcement point communicates with policy decision points to determine applicable policies and reports back on policy violations or enforcement status. This feedback loop enables automated policy management and reduces the manual complexity of managing hierarchical policies across multiple administrative entities.
Data Source
AI summary
In one embodiment, a first administrative entity having first members may initiate an operated shared workspace having a policy control engine. The first administrative entity may configure a first set of policies regarding workspace access, while a second administrative entity, having second members, may configure a second set of policies regarding workspace access. The policy control engine may then apply the first policies to the first and second members, and also may apply one or more policies of the second set of policies to the second members in response to the respective policies being stricter than corresponding policies of the first set of policies.


