Policy Stratification for Correct ACL Conversion

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current RBAC policy management systems fail to correctly convert policy sets including both positive and negative policies into a single ACL, as they do not adequately consider inclusion relationships between subject sets, leading to incorrect access control settings and potential breaches.

Innovation Solution

A policy management system that includes a role information storing unit, a policy description storing unit, a policy stratifying unit, and a policy ordering unit, which generates a policy hierarchy based on inclusion relationships between subject sets and totally orders policy sets to ensure correct conversion of policy sets into a single ACL.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of manufacture

If policies are converted into ACL without considering inclusion relationships between subject sets, then the conversion process is simple, but the access control settings become incorrect and may lead to security breaches

Engineering Contradiction:
Improveease of policy conversionVSAvoidcorrectness of access control settings
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The patent applies preliminary action by performing policy stratification before ACL conversion. The policy stratifying unit divides policies into hierarchical layers based on subject set inclusion relationships before the conversion process, ensuring that the ordering information is established in advance. This prevents incorrect access control settings while maintaining a systematic conversion process.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces policy stratification as an intermediary step between policy storage and ACL conversion. The policy hierarchy information acts as a mediator that carries ordering information through the conversion process, ensuring that exception policies are properly prioritized over general policies without requiring complex real-time calculations during access control decisions.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If policies are stratified based on inclusion relationships between subject sets, then the correctness of access control settings is improved, but the device complexity increases

Engineering Contradiction:
Improvecorrectness of access control settingsVSAvoidcomplexity of policy management system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies segmentation by dividing the policy management functionality into distinct units: a policy stratifying unit that handles hierarchy construction, and a policy ordering unit that handles ACL conversion. This modular approach isolates the complexity into specific components rather than distributing it throughout the entire system, making the complexity manageable and localized.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent adds a hierarchical dimension to policy representation by introducing policy layers based on subject set inclusion relationships. This transforms the flat policy set into a multi-layered structure where policies are organized from general to specific, enabling correct ACL generation without requiring complex inter-policy relationships to be tracked in the original dimension.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Ease of operation

If policy sets including positive and negative policies are converted without proper ordering, then the conversion is straightforward, but the principle/exception relationship is not maintained

Engineering Contradiction:
Improveease of policy conversionVSAvoidprinciple/exception relationship information
Core Design Contradiction:
Ease of operationVSLoss of information

Solution Approach 1:

The patent performs preliminary stratification of policies into hierarchical layers based on subject set inclusion relationships before conversion. This preliminary action captures the principle/exception relationship information in the policy hierarchy structure, ensuring it is preserved throughout the conversion process and correctly reflected in the generated ACL.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent copies the hierarchical structure information from the policy layer to the ACL generation process. By maintaining and transmitting the policy hierarchy information through the conversion process, the system preserves the principle/exception relationships without requiring the original policy structure to be directly embedded in the ACL, thus preventing information loss.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS8875221B2Policy management apparatus, policy management system, and method and program used for the same
Publication Date: 2014.10.28 NEC CORP
  • US8875221B2 patent drawing
  • US8875221B2 patent drawing
  • US8875221B2 patent drawing

AI summary

There are provided a role information storing unit (11) that stores role information including information indicative of subject sets, and information capable of specifying inclusion relationships between subject sets, a policy description storing unit (12) that stores policy descriptions including information indicative of policies and information for identifying subject sets to which the policies are to be applied, a policy stratifying unit (13) that generates a policy hierarchy in which two or more policies are stratified based on inclusion relationships between subject sets to which each policy is applied, and a policy ordering unit (14) that totally orders policy sets made of the two or more policies to be totally ordered based on information indicative of the policy hierarchy while maintaining a higher/lower relationship in a hierarchy.