Purpose-Based Access Control via Dynamic Constraint Evaluation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing access control systems fail to provide purpose-based access control and environmental controls, leading to increased risks of data breaches and inefficient management of access rights.

Innovation Solution

The implementation of purpose-based access control systems that tie access to assets to specific business purposes, allowing real-time re-assessment of access rights and enabling unrestricted collaboration while maintaining data security through environmental constraints.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional access control systems are used to manage access rights, then access management can be implemented, but the systems cannot provide purpose-based access control and environmental controls, leading to increased risks of data breaches

Engineering Contradiction:
Improvedata securityVSAvoidpurpose-based access control capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments access control into multiple independent components: purpose definitions, environmental constraints, access requests, and authorization decisions. This allows the system to evaluate each aspect separately and combine them for comprehensive purpose-based access control, resolving the contradiction between traditional access control limitations and the need for purpose-based control.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system dynamically evaluates access requests by assessing purposes and environmental constraints in real-time rather than using static access rights. This dynamic approach enables the system to adapt to changing conditions and provide purpose-based access control while maintaining data security, overcoming the rigidity of traditional access control systems.

Inventive Principle:
Principle #15Dynamics

2Ease of operation

If access control rules are manually managed, then access rights can be controlled, but the volume of access requests increases with personalization and consent management, making manual handling inefficient

Engineering Contradiction:
Improveaccess rights managementVSAvoidprocessing efficiency
Core Design Contradiction:
Ease of operationVSProductivity

Solution Approach 1:

The system enables self-service access control by automatically evaluating access requests against defined purposes and environmental constraints without manual intervention. The automated evaluation process handles increasing volumes of access requests efficiently, resolving the contradiction between ease of manual management and processing efficiency.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces manual mechanical access control processes with an automated computational system that evaluates purposes and environmental constraints. This substitution of manual operations with automated processing significantly improves productivity while maintaining ease of access rights management through systematic evaluation.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Productivity

If unrestricted collaboration is allowed across an organization, then productivity increases, but the risk of inappropriate disclosure of sensitive data also increases

Engineering Contradiction:
Improvecollaboration efficiencyVSAvoiddata disclosure risk
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The system introduces an intermediary evaluation layer between collaboration requests and data access. This intermediary assesses purposes and environmental constraints to determine whether access should be granted, enabling unrestricted collaboration while preventing inappropriate data disclosure through automated purpose-based evaluation.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system changes the parameters of access control from static user roles to dynamic purpose and environmental constraint evaluations. This parameter change allows the system to permit broad collaboration when purposes are appropriate while automatically restricting access when disclosure risks arise, resolving the contradiction between collaboration efficiency and data protection.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS12292987B2Methods and systems for purpose-based access control
Publication Date: 2025.05.06 THE REGENCE GROUP
  • US12292987B2 patent drawing
  • US12292987B2 patent drawing
  • US12292987B2 patent drawing

AI summary

Systems and methods for purpose-based access control are provided. In one embodiment, a method for determining access to an asset comprises receiving, from a user, an access request for the asset, the access request specifying a purpose for accessing the asset, and authorizing access to the asset if the purpose is approvingly linked to the asset. In this way, unrestricted collaboration across an organization may be allowed without risking inappropriate disclosure.