Centralized Policy Server for Document and Application Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current access control methods, such as Unix permissions and Access Control Lists (ACLs), lack flexibility and universality, failing to effectively manage access to files and non-file system objects, and do not provide centralized control over application program usage.

Innovation Solution

A centrally managed rule-based system that uses a policy server to enforce access and usage controls through policy enforcers installed on client systems and servers, allowing for autonomous operation and comprehensive management of document access and application usage.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If Unix permissions or ACLs are used for access control, then file system access can be managed, but control over non-file system objects and application usage cannot be achieved

Engineering Contradiction:
Improvecontrol scopeVSAvoidaccess control effectiveness
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent implements a universal access control system where a single policy framework can manage access to multiple object types (files, emails, web pages, etc.) and control both user and application program access. The policy server evaluates access requests against centrally managed rules regardless of the object type or requester type, providing unified control across the entire information management system.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Ease of operation

If ACLs are stored in files or extended attributes, then access control can be implemented, but centralized management and portability across different file systems are lost

Engineering Contradiction:
Improveaccess control implementationVSAvoidportability
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The patent introduces a policy server as an intermediary between the access control mechanism and the information management system. The policy server stores and manages access control rules centrally, receiving access requests from policy enforcers and returning decisions. This intermediary layer enables centralized management while maintaining portability across different systems and file systems, as the policy server can be deployed independently of specific file system implementations.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If operating system permission checks are used, then file access control can be enforced, but application program usage cannot be controlled

Engineering Contradiction:
Improvefile access controlVSAvoidapplication usage control
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent adds a new dimension to access control by introducing application program identification and control capabilities. The policy server evaluates not only user permissions but also application program identities and authorized operations. This dimensional extension allows the system to control both user-level and application-level access, enabling fine-grained control over what applications can do with protected objects beyond traditional file system permissions.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

4Extent of automation

If access control rules are managed locally on each system, then autonomous operation is possible, but centralized policy management and consistency across systems cannot be achieved

Engineering Contradiction:
Improveautonomous operationVSAvoidpolicy management
Core Design Contradiction:
Extent of automationVSEase of operation

Solution Approach 1:

The patent merges centralized policy management with distributed enforcement by combining a central policy server with local policy enforcers on client systems. The policy server handles centralized rule creation, storage, and distribution, while policy enforcers handle local evaluation and autonomous decision-making. This combination allows policies to be managed centrally for consistency while enabling autonomous operation at the enforcement level, resolving the contradiction between centralized control and local autonomy.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS9866594B2Enforcing policy-based application and access control in an information management system
Publication Date: 2018.01.09 NEXTLABS INC
  • US9866594B2 patent drawing
  • US9866594B2 patent drawing
  • US9866594B2 patent drawing

AI summary

A method and apparatus for controlling document access and application usage using centrally managed rules. The rules are stored and manipulated in a central rule database via a rule server. Policy enforcers are installed on client systems and/or on servers and perform document access and application usage control for both direct user document accesses and application usage, and application program document accesses by evaluating the rules sent to the policy enforcer. The rule server decides which rules are required by each policy enforcer. A policy enforcer can also perform obligation and remediation operations as a part of rule evaluation. Policy enforcers on client systems and servers can operate autonomously, evaluating policies that have been received, when communications have been discontinued with the rule server.