Centralized Policy Server for Document and Application Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current access control methods, such as Unix permissions and Access Control Lists (ACLs), lack flexibility and universality, failing to effectively manage access to files and non-file system objects, and do not provide centralized control over application program usage.
Innovation Solution
A centrally managed rule-based system that uses a policy server to enforce access and usage controls through policy enforcers installed on client systems and servers, allowing for autonomous operation and comprehensive management of document access and application usage.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If Unix permissions or ACLs are used for access control, then file system access can be managed, but control over non-file system objects and application usage cannot be achieved
Solution Approach 1:
The patent implements a universal access control system where a single policy framework can manage access to multiple object types (files, emails, web pages, etc.) and control both user and application program access. The policy server evaluates access requests against centrally managed rules regardless of the object type or requester type, providing unified control across the entire information management system.
2Ease of operation
If ACLs are stored in files or extended attributes, then access control can be implemented, but centralized management and portability across different file systems are lost
Solution Approach 1:
The patent introduces a policy server as an intermediary between the access control mechanism and the information management system. The policy server stores and manages access control rules centrally, receiving access requests from policy enforcers and returning decisions. This intermediary layer enables centralized management while maintaining portability across different systems and file systems, as the policy server can be deployed independently of specific file system implementations.
3Reliability
If operating system permission checks are used, then file access control can be enforced, but application program usage cannot be controlled
Solution Approach 1:
The patent adds a new dimension to access control by introducing application program identification and control capabilities. The policy server evaluates not only user permissions but also application program identities and authorized operations. This dimensional extension allows the system to control both user-level and application-level access, enabling fine-grained control over what applications can do with protected objects beyond traditional file system permissions.
4Extent of automation
If access control rules are managed locally on each system, then autonomous operation is possible, but centralized policy management and consistency across systems cannot be achieved
Solution Approach 1:
The patent merges centralized policy management with distributed enforcement by combining a central policy server with local policy enforcers on client systems. The policy server handles centralized rule creation, storage, and distribution, while policy enforcers handle local evaluation and autonomous decision-making. This combination allows policies to be managed centrally for consistency while enabling autonomous operation at the enforcement level, resolving the contradiction between centralized control and local autonomy.
Data Source
AI summary
A method and apparatus for controlling document access and application usage using centrally managed rules. The rules are stored and manipulated in a central rule database via a rule server. Policy enforcers are installed on client systems and/or on servers and perform document access and application usage control for both direct user document accesses and application usage, and application program document accesses by evaluating the rules sent to the policy enforcer. The rule server decides which rules are required by each policy enforcer. A policy enforcer can also perform obligation and remediation operations as a part of rule evaluation. Policy enforcers on client systems and servers can operate autonomously, evaluating policies that have been received, when communications have been discontinued with the rule server.


