Policy Enforcer for Document Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current access control methods, such as Unix permissions and Access Control Lists (ACLs, are inflexible and limited to file systems, failing to provide comprehensive control over user access and application usage across diverse computer environments, including non-file system objects and applications.

Innovation Solution

A centrally managed rule-based system using a policy server and policy enforcers installed on client systems and servers to evaluate and enforce access and usage policies for documents and applications, allowing for autonomous operation even when disconnected from the central server.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If Unix permissions or ACLs are used for access control, then file system access can be managed, but the system lacks flexibility and cannot control access to non-file system objects or application usage

Engineering Contradiction:
Improvecontrol scopeVSAvoidsystem architecture
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements a universal policy enforcement framework that extends access control beyond traditional file systems to include non-file system objects and application usage. The policy enforcement point evaluates policies against diverse objects (files, emails, web pages, applications) using a common policy language, achieving multi-functional control without requiring separate mechanisms for each object type.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent introduces a policy enforcement point as an intermediary layer between users/applications and protected objects. This mediator evaluates policies centrally managed by a policy administrator and enforces them across diverse objects, bridging the gap between simple permission systems and the need for comprehensive, flexible control without direct complexity in the access control logic itself.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If ACLs are built into the operating system kernel, then file access control is integrated, but the system is not portable and control information may be lost when copying files between file systems or operating systems

Engineering Contradiction:
Improvecontrol consistencyVSAvoidportability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent extracts access control policies from the operating system kernel and file system-specific implementations, placing them in a portable policy language that can be centrally managed and applied across different file systems and operating systems. This separation allows control information to be preserved and transferred when files are copied between environments.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent creates a universal policy framework that works across multiple file systems and operating systems through a common policy language. The policy enforcement point interprets these universal policies regardless of the underlying file system or OS, ensuring consistent control behavior and portability of access control information across diverse platforms.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Adaptability or versatility

If traditional access control methods are used, then user access can be restricted, but application program access and time/location-based control are not available

Engineering Contradiction:
Improvecontrol dimensionsVSAvoidpolicy evaluation complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements dynamic policy evaluation that considers multiple dimensions including user identity, application program, time of day, and location. The policy enforcement point dynamically evaluates policies against these varying parameters, allowing access control to adapt to different contexts (e.g., different permissions at different times or locations) without requiring static, overly complex pre-configured rules for every scenario.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent segments the policy evaluation process into distinct components: policy definition, policy distribution, and policy enforcement. This segmentation allows complex multi-dimensional control requirements to be broken down into manageable policy rules that can be centrally managed and independently evaluated against different criteria (user, application, time, location) without overwhelming system complexity.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS10536485B2Enforcing control policies in an information management system with two or more interactive enforcement points
Publication Date: 2020.01.14 NEXTLABS INC
  • US10536485B2 patent drawing
  • US10536485B2 patent drawing
  • US10536485B2 patent drawing

AI summary

A method and apparatus for controlling document access and application usage using centrally managed rules. The rules are stored and manipulated in a central rule database via a rule server. Policy enforcers are installed on client systems and/or on servers and perform document access and application usage control for both direct user document accesses and application usage, and application program document accesses by evaluating the rules sent to the policy enforcer. The rule server decides which rules are required by each policy enforcer. A policy enforcer can also perform obligation and remediation operations as a part of rule evaluation. Policy enforcers on client systems and servers can operate autonomously, evaluating policies that have been received, when communications have been discontinued with the rule server.