Project Zone Access Control Through Proxy Services

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing access control systems for computing resources in project environments are complex and inefficient, often leading to unauthorized data access and cumbersome administration due to user-focused approaches, which fail to account for overlapping project needs and device configurations.

Innovation Solution

A system that generates zones with defined access rights for datasets and tools, using a proxy service to manage access policies dynamically, allowing rapid adjustments and minimizing data breaches through masking policies, while supporting interoperability across various applications and devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If user-focused access control approaches are used, then access rights can be granted to users, but this leads to improper access to projects not contemplated when permission was granted and requires cumbersome administration to monitor and maintain user properties

Engineering Contradiction:
Improveaccess control administrationVSAvoiddata security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments access control from user-level to zone-level. Instead of managing user properties and permissions directly, the system creates zones with defined access rights that encapsulate project data and tools. This segmentation isolates security management at the zone level, preventing users from accessing projects not contemplated when permission was granted, while simplifying administration by reducing the number of individual user properties to monitor.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If high permission levels are granted to users, then users can access computing resources, but higher credentialed users may share data inadvertently or in contravention of existing policies

Engineering Contradiction:
Improveuser access flexibilityVSAvoidunauthorized data access
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces zones as intermediary structures between users and computing resources. Zones act as mediators that enforce access policies independently of user credential levels. Even high-credentialed users must access resources through zones, which filter and control their access rights. This intermediary layer prevents data sharing in contravention of policies while maintaining user access flexibility within defined boundaries.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Device complexity

If existing access control systems are used, then access can be managed, but the complexity of access right interactions within teams and overlapping needs across multiple projects makes administration challenging

Engineering Contradiction:
Improveaccess control system structureVSAvoidaccess control administration
Core Design Contradiction:
Device complexityVSEase of operation

Solution Approach 1:

The patent creates universal zones that can serve multiple functions and accommodate overlapping project needs. Zones are designed to be multi-functional, supporting different project requirements, team structures, and access patterns within a single framework. This universality simplifies administration by providing a unified approach to managing access rights across diverse scenarios, reducing the complexity of interacting with multiple separate access control mechanisms.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12363049B2System and method for controlling access to project data and to computing resources therefor
Publication Date: 2025.07.15 THE TORONTO DOMINION BANK
  • US12363049B2 patent drawing
  • US12363049B2 patent drawing
  • US12363049B2 patent drawing

AI summary

A server device, system, method, and for controlling access to project resources is disclosed. The disclosure includes a processor, and a communications module and a memory coupled to the processor. The memory, when executed by the processor, causes the processor to generate a plurality of zones for a project, each zone defining a set of access rights to: i) a database; and ii) at least one tool. The processor configures each set of access rights to allow a proxy service to access the zones, and receives, from a client device and via the proxy service, an access query to access at least one zone. The processor provides the client device access to, via the proxy service, the at least one dataset and at least one tool of the at least one zone.