Role-Based Access Control Conflict Resolution via Virtual Exceptional Roles
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing role-based access control systems struggle to manage conflicts when a user is assigned multiple roles from independent role hierarchies, leading to the need for redefining authority permissions for each user, which is cumbersome and inefficient.
Innovation Solution
An access control method and system that stores subject assignments, authority permissions, and role hierarchies, detects conflicts between roles, and generates an exceptional authority permission assignment for a virtual role, resolving conflicts by inheriting permissions from multiple roles and allowing user input to define conflicting permissions as exceptions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If authority permissions are redefined for each user assigned multiple roles, then conflict resolution between roles is achieved, but the complexity and time required for access control management increases significantly
Solution Approach 1:
The patent merges the authority permissions of multiple roles into a unified access control list for users assigned multiple roles. The system automatically combines the access rights from all assigned roles and resolves conflicts by applying a defined priority order, eliminating the need to manually redefine permissions for each user while maintaining reliable conflict resolution.
Solution Approach 2:
The patent creates a universal access control management mechanism that handles multiple roles and their conflicts through a single systematic approach. The system universally applies role priority ordering and automatic permission merging across all users, regardless of how many roles they are assigned, making the solution scalable and consistent throughout the organization.
2Manufacturing precision
If all authority permissions are rewritten for each user with multiple roles, then precise access control is achieved, but the time and effort required for access control rule creation increases
Solution Approach 1:
The patent performs preliminary actions by pre-defining role priorities and establishing the hierarchy of roles before users are assigned multiple roles. When a user is assigned multiple roles, the system automatically applies the pre-established priority order to resolve conflicts, eliminating the need for time-consuming manual permission rewriting while maintaining precise access control.
Solution Approach 2:
The system enables self-service automatic conflict resolution by automatically merging and prioritizing authority permissions when users are assigned multiple roles. The access control system autonomously handles the combination of permissions from different roles according to the defined priority order, without requiring manual intervention from administrators to rewrite permissions for each user.
3Ease of operation
If a single tree structure organization is used for access control, then the system is simple to manage, but it cannot handle conflicts between roles from multiple independent hierarchies
Solution Approach 1:
The patent extends the traditional single-dimension organizational hierarchy to multiple dimensions by allowing users to be assigned roles from multiple independent role hierarchies simultaneously. The system handles conflicts between these multi-dimensional roles by applying priority ordering within each hierarchy and then combining the results, enabling the management of complex multi-hierarchy structures while maintaining operational simplicity.
Data Source
AI summary
Authority permission grants/denials associated with each of a plurality of roles (R1, R2, . . . , Rm) assigned to one subject are derived by inheritance based on a subject assignment associating a role and a subject, an authority permission assignment associating a role, an authority permission, and a grant/denial, and a role hierarchy indicating an inheritance relation between roles. Among the derived authority permission grants/denials, grants/denials of authority permissions (A1, A2, . . . , An) which are each derived from two or more different roles (R1, R2, . . . , Rm) and which are each granted to one of the plurality of roles R1, R2 . . . Rm but denied to another one of the plurality of roles R1, R2 . . . Rm are determined in accordance with an input. As exceptional authority permission assignment for a virtual exceptional role constituted of a combination of roles (R1, R2, . . . , Rm), authority permission grants/denials associated with each role (R1, R2, . . . , Rm) are derived by inheritance based on the role hierarchy, authority permission assignment, and the exceptional authority permission assignment.


