RBAC to ACL Policy Translation via Intermediary Layer

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems lack the ability to translate role-based access control (RBAC) policies to resource authorization policies, such as ACL-based applications, leading to manageability and complexity issues in large networks.

Innovation Solution

A generic RBAC system is defined that enables the translation of RBAC roles to resource authorization policies, using mechanisms like Windows Authorization Manager to manage object types and relationships, allowing for the mapping of RBAC policies to ACLs and other authorization enforcement mechanisms.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If traditional domain-based access control lists (ACL) are used for resource authorization, then resource access control can be implemented, but manageability and complexity problems arise as the number of resources and users proliferate

Engineering Contradiction:
Improvemanageability of access controlVSAvoidcomplexity of access control system
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary translation layer that converts RBAC policy definitions into RAP/ACL formats. This intermediary component (translation service or gateway) mediates between the simplified RBAC model and the traditional ACL system, allowing administrators to use role-based policies while the system automatically handles the complexity of mapping to underlying ACL structures.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates a virtual copy or representation of the RBAC policy model that can be translated into RAP/ACL formats. Instead of directly managing complex ACLs, the system maintains a simplified RBAC policy copy that can be automatically transformed into the required ACL structures, reducing administrative burden while maintaining compatibility with existing systems.

Inventive Principle:
Principle #26Copying

2Ease of operation

If role-based access control (RBAC) policy is implemented to reduce complexity, then security administration becomes easier, but there is no way to translate RBAC roles to resource authorization policy (RAP) such as ACL-based applications

Engineering Contradiction:
Improveease of security administrationVSAvoidcompatibility with existing authorization mechanisms
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The patent introduces an intermediary translation layer that converts RBAC policy definitions into RAP/ACL formats. This intermediary component (translation service or gateway) mediates between the simplified RBAC model and the traditional ACL system, allowing administrators to use role-based policies while the system automatically handles the complexity of mapping to underlying ACL structures.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent transforms the parameter representation of access control policies from detailed ACL entries to aggregated RBAC role definitions. By changing the parameter granularity from individual user-resource permissions to role-based permission sets, the system achieves both simplification and compatibility through automated translation.

Inventive Principle:
Principle #35Parameter changes

3Adaptability or versatility

If RBAC is used to dynamically regulate user actions according to flexible functions and relationships, then authorization flexibility improves, but integration with existing RAP systems becomes difficult

Engineering Contradiction:
Improveflexibility of authorizationVSAvoidcomplexity of integration with existing systems
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary translation layer that converts RBAC policy definitions into RAP/ACL formats. This intermediary component (translation service or gateway) mediates between the simplified RBAC model and the traditional ACL system, allowing administrators to use role-based policies while the system automatically handles the complexity of mapping to underlying ACL structures.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the authorization system into distinct functional layers: the flexible RBAC policy definition layer and the existing RAP/ACL enforcement layer. The translation service acts as a bridge between these segments, allowing each layer to operate independently with its own strengths while maintaining overall system integration.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS8381306B2Translating role-based access control policy to resource authorization policy
Publication Date: 2013.02.19 MICROSOFT TECHNOLOGY LICENSING LLC
  • US8381306B2 patent drawing
  • US8381306B2 patent drawing
  • US8381306B2 patent drawing

AI summary

Translation of role-based authoring models for managing RBAC “roles” to resource authorization policy (RAP), such as ACL-based applications, is provided. A generic RBAC system is defined from which mappings to other authorization enforcement mechanism make possible the translation of RBAC “roles” to resource authorization policies applied to resources managed by a resource manager, e.g., a file system resource manager. An implementation is described that uses Windows Authorization Manager as a storage mechanism and object model to manage object types and relationships translated from an RBAC system.