Relationship-Based Access Control for Digital Assets

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cybersecurity measures face challenges in efficiently securing computing systems due to the variety of cyberattacks and the need to balance costs and benefits of different security efforts, while also managing access to digital assets effectively.

Innovation Solution

The implementation of an access control system that automatically grants access to supplementary digital assets when a user already has access to a primary asset, based on recognized relationships between the assets, without requiring separate sign-ins or authorization checks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If traditional access control mechanisms are used for each digital asset, then security is maintained, but usability deteriorates due to multiple separate sign-ins and authorization checks

Engineering Contradiction:
ImproveusabilityVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements a universal access control mechanism where a single authorization to a primary digital asset automatically extends to related supplementary assets. The access control system determines relationships between assets and grants unified access, eliminating the need for separate sign-ins and authorization checks for each asset, thereby improving usability while maintaining security through relationship-based verification

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Ease of operation

If file share or share link mechanisms are used to provide access, then accessibility improves, but security risk increases

Engineering Contradiction:
ImproveaccessibilityVSAvoidsecurity risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an access control system as an intermediary that mediates between users and digital assets. Instead of direct access through file shares or links, the system verifies relationships between assets and authorizes access based on these relationships, providing controlled accessibility while mitigating security risks associated with traditional sharing mechanisms

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If multiple security mechanisms are layered for defense in depth, then security coverage improves, but system complexity increases

Engineering Contradiction:
Improvesecurity coverageVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges multiple security verification steps into a single relationship-based authorization process. By determining relationships between digital assets once and using this determination across multiple access requests, the system maintains comprehensive security coverage while reducing the complexity of implementing multiple separate security mechanisms

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentEP4004786B1Related asset access based on proven primary asset access
Publication Date: 2025.04.02 MICROSOFT TECHNOLOGY LICENSING LLC
  • EP4004786B1 patent drawingFigure 1~3
  • EP4004786B1 patent drawingFigure 4~6
  • EP4004786B1 patent drawingFigure 7~8

AI summary

Access control enhancements reduce security risks and management burdens when a user with access to a primary asset seeks access to a related supplementary asset. When a sufficient proof of access to the primary asset is provided, and the relationship of the primary and supplementary assets is recognized, access to the supplementary asset is granted without requiring a separate sign-in, a permission query to the supplementary asset's owner, or an authorization through an authenticated identity of the requestor, for example. Automatic access to the supplementary asset can be granted without the security risks inherent in a file share or a share link. In particular, a developer with access to one component of a project can be automatically and conveniently granted access to the rest of the project. Likewise, a custom machine learning model for autocompletion becomes accessible to all developers working on the repository source used to train the model.