Scenario-Based Access Control for Resource Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing access control systems face challenges in managing access to large numbers of resources and users, leading to complexity and inefficiency in granting and revoking access.
Innovation Solution
The implementation of access control scenarios that define specific conditions and triggers for granting access to resources, allowing for automated and controlled access management across multiple assets and users.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional access control systems are used to manage individual resources, then access to each resource can be controlled, but the complexity of managing access across tens of thousands of resources increases significantly
Solution Approach 1:
The patent combines multiple individual resource access controls into unified access scenarios. Instead of managing access to each resource separately, the system groups resources into scenarios (e.g., 'HR Onboarding Scenario', 'IT Incident Response Scenario') that define predefined access patterns. This merging approach maintains reliable access control while significantly reducing management complexity by handling groups of resources as unified entities.
Solution Approach 2:
The patent creates universal access scenarios that can be applied across multiple resources and user types. A single scenario definition can govern access to numerous different resources (files, systems, applications) and serve multiple user roles simultaneously. This multi-functionality allows the same access control mechanism to serve diverse access needs, reducing the overall complexity of the access control system.
2Reliability
If access control is managed individually for each resource, then precise control is achieved, but the effort to keep access controls current increases
Solution Approach 1:
The patent implements preliminary action by pre-defining access scenarios with predetermined access rules, user groups, and resource associations. These scenarios are configured in advance with all necessary access control parameters, so when users need access, the system simply applies the pre-configured scenario rather than individually configuring each resource. This preliminary preparation dramatically reduces the time and effort required to maintain access controls while preserving precise control over who accesses what.
3Adaptability or versatility
If traditional access control systems are used, then individual resource access can be granted, but scalability to large numbers of assets and users is limited
Solution Approach 1:
The patent segments the access control system into hierarchical layers: scenarios at the top level, user groups in the middle, and individual resources at the bottom. This segmentation allows the system to scale efficiently by operating at the scenario level for bulk access management while maintaining the ability to drill down to individual resources when needed. The segmented structure enables the system to handle tens of thousands of resources and users without proportionally increasing complexity.
Data Source
AI summary
Methods, systems, and computer programs are presented for managing access to resources using scenarios. One method includes an operation for storing first scenario data received for a first control scenario. The first scenario data comprises a control scenario identifier, a first resource, an authorization control, and a scenario trigger that defines an event that causes an activation of the first control scenario for providing access to the first resource. Further, the method includes operations for monitoring for an occurrence of the scenario trigger and detecting an occurrence of the event associated with the scenario trigger. Further, the method determines, in response to the occurrence of the event, a set of users authorized to access the first resource, including accessing the first scenario data to determine the set of users associated with the authorization control. Furthermore, access is provided to the set of users based on the determining.


