Automated RBAC Model Generation via Cladistics Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The Role-Based Access Control (RBAC) model becomes unwieldy and labor-intensive in large, complex computer systems, especially in hierarchical RBAC systems, due to the difficulty in defining roles and their permissions, and the need for frequent revisions with changes in organizational structure or responsibilities.

Innovation Solution

The system automatically generates an RBAC model using cladistics analysis to determine role perspective relationships between users, eliminating the need for manual interviews and data reviews by treating user permissions as characteristics and applying statistical methodologies to create a cladogram-based model.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of manufacture

If manual interview processes and data review are used to define roles and permissions, then the RBAC model can be created, but the process becomes labor intensive and time consuming

Engineering Contradiction:
Improveease of RBAC model creationVSAvoidtime required for role definition
Core Design Contradiction:
Ease of manufactureVSLoss of time

Solution Approach 1:

The system automatically generates RBAC models by analyzing existing user permissions and applying cladistics algorithms, eliminating the need for manual interviews and data review. The system serves itself by autonomously discovering role relationships and generating the complete RBAC model without human intervention in the analysis process.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces manual mechanical processes (interviews, data review, manual role definition) with automated computational mechanisms. The system uses software-based cladistics analysis to process permission data and generate roles, substituting human labor with algorithmic processing.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Adaptability or versatility

If hierarchical RBAC models are developed to manage complex organizations, then access control can be implemented, but the complexity of defining roles and relationships increases

Engineering Contradiction:
Improvecapability to handle complex organizationsVSAvoidcomplexity of role definition process
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system automatically analyzes existing user permissions and applies cladistics algorithms to discover hierarchical role relationships, eliminating the need for manual definition of complex role structures. The system self-determines the appropriate hierarchy based on actual permission patterns.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent transforms the approach from manual qualitative role definition to automated quantitative analysis of permission parameters. By analyzing permission characteristics and applying statistical algorithms, the system automatically determines role relationships and hierarchy levels.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If RBAC models are manually revised to accommodate organizational changes, then the model remains accurate, but the maintenance effort and time increase

Engineering Contradiction:
Improveaccuracy of RBAC modelVSAvoidefficiency of model maintenance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system continuously monitors and analyzes changes in user permissions and automatically updates the RBAC model accordingly. This feedback mechanism ensures the model remains accurate reflecting current organizational structure without requiring manual revision processes.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system automatically detects organizational changes through permission analysis and self-updates the RBAC model, eliminating the need for manual maintenance. The model adapts to changes autonomously by reanalyzing permission patterns.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS7650633B2Automated organizational role modeling for role based access controls
Publication Date: 2010.01.19 X CORP
  • US7650633B2 patent drawing
  • US7650633B2 patent drawing
  • US7650633B2 patent drawing

AI summary

Generally speaking, systems, methods and media for automatically generating a role based access control model (RBAC) for an organizational environment with a role based access control system such as a hierarchical RBAC (HRBAC) system are disclosed. Embodiments may include a method for generating an RBAC model. Embodiments of the method may include accessing existing permissions granted to users of an organizational environment and analyzing the permissions to create permission characteristics. Embodiments of the method may also include performing cladistics analysis on the permission characteristics to determine role perspective relationships between individual users of the organizational environment. Embodiments of the method may also include generating an RBAC model based on the determined role perspective relationships between individual users of the organizational environment. Further embodiments of the method may include where generating the RBAC model includes generating a cladogram based on the determined role perspective relationships.