Relationship-Based Access Control for Digital Assets
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing cybersecurity measures face challenges in efficiently securing computing systems due to the variety of cyberattacks and the need to balance costs and benefits of different security efforts, while also managing access to digital assets effectively.
Innovation Solution
The implementation of an access control system that automatically grants access to supplementary digital assets when a user already has access to a primary asset, based on recognized relationships between the assets, without requiring separate sign-ins or authorization checks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If traditional access control mechanisms are used for each digital asset, then security is maintained, but usability deteriorates due to multiple separate sign-ins and authorization checks
Solution Approach 1:
The patent implements a universal access control mechanism where a single authorization to a primary digital asset automatically extends to related supplementary assets. The access control system determines relationships between assets and grants unified access, eliminating the need for separate sign-ins and authorization checks for each asset, thereby improving usability while maintaining security through relationship-based verification
2Ease of operation
If file share or share link mechanisms are used to provide access, then accessibility improves, but security risk increases
Solution Approach 1:
The patent introduces an access control system as an intermediary that mediates between users and digital assets. Instead of direct access through file shares or links, the system verifies relationships between assets and authorizes access based on these relationships, providing controlled accessibility while mitigating security risks associated with traditional sharing mechanisms
3Reliability
If multiple security mechanisms are layered for defense in depth, then security coverage improves, but system complexity increases
Solution Approach 1:
The patent merges multiple security verification steps into a single relationship-based authorization process. By determining relationships between digital assets once and using this determination across multiple access requests, the system maintains comprehensive security coverage while reducing the complexity of implementing multiple separate security mechanisms
Data Source
Figure 1~3
Figure 4~6
Figure 7~8
AI summary
Access control enhancements reduce security risks and management burdens when a user with access to a primary asset seeks access to a related supplementary asset. When a sufficient proof of access to the primary asset is provided, and the relationship of the primary and supplementary assets is recognized, access to the supplementary asset is granted without requiring a separate sign-in, a permission query to the supplementary asset's owner, or an authorization through an authenticated identity of the requestor, for example. Automatic access to the supplementary asset can be granted without the security risks inherent in a file share or a share link. In particular, a developer with access to one component of a project can be automatically and conveniently granted access to the rest of the project. Likewise, a custom machine learning model for autocompletion becomes accessible to all developers working on the repository source used to train the model.