Policy Control Engine for Hierarchical Workspace Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current shared online workspace environments struggle to enforce hierarchical collaboration policies across different administrative entities, leading to inconsistencies and lack of control over access and activities, particularly when guests from one entity interact with resources governed by another entity's policies.

Innovation Solution

Implementing a policy control engine that applies the stricter policies of participating entities to ensure seamless coexistence of individual policies within a shared resource, allowing each administrative entity to manage access and activities according to their defined rules.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a guest account system is used to allow external clients to access the workspace, then collaboration with outside entities is enabled, but the external clients' own policies are not enforced and they are governed only by the administrative entity's policies

Engineering Contradiction:
Improvecollaboration capabilityVSAvoidpolicy enforcement
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces a policy enforcement point (PEP) as an intermediary component that sits between external clients and the workspace resources. This PEP acts as a mediator that receives policy decisions from the external client's administrative entity and enforces them within the workspace environment, thereby enabling policy enforcement for guest accounts without preventing collaboration.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the policy enforcement mechanism into separate components: a policy decision point (PDP) that determines which policies apply, and a policy enforcement point (PEP) that actually implements the policies. This segmentation allows the system to handle multiple administrative entities' policies independently and enforce them appropriately for each external client.

Inventive Principle:
Principle #1Segmentation

2Reliability

If hierarchical collaboration policies are implemented to enforce multiple administrative entities' policies, then policy control and security are improved, but system complexity increases due to the need to manage and reconcile multiple policy sets

Engineering Contradiction:
Improvepolicy controlVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The policy enforcement point serves as an intermediary that simplifies the complexity by providing a standardized interface for policy enforcement. Instead of requiring the workspace system to directly manage and reconcile multiple complex policy sets from different administrative entities, the PEP handles this complexity internally while presenting a unified enforcement mechanism to the workspace.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements feedback mechanisms where the policy enforcement point communicates with policy decision points to determine applicable policies and reports back on policy violations or enforcement status. This feedback loop enables automated policy management and reduces the manual complexity of managing hierarchical policies across multiple administrative entities.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS8245141B1Hierarchical collaboration policies in a shared workspace environment
Publication Date: 2012.08.14 CISCO TECHNOLOGY INC
  • US8245141B1 patent drawing
  • US8245141B1 patent drawing
  • US8245141B1 patent drawing

AI summary

In one embodiment, a first administrative entity having first members may initiate an operated shared workspace having a policy control engine. The first administrative entity may configure a first set of policies regarding workspace access, while a second administrative entity, having second members, may configure a second set of policies regarding workspace access. The policy control engine may then apply the first policies to the first and second members, and also may apply one or more policies of the second set of policies to the second members in response to the respective policies being stricter than corresponding policies of the first set of policies.