Self-Declared User Attribute Access Control System

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional security systems rely on administrator-defined criteria for filtering information, which can lead to administrative overhead and increased risk of unauthorized access, especially in scenarios where the administrator is unaware of user identities or affiliations, potentially violating policies or regulations.

Innovation Solution

A method allowing users to self-declare permission attributes, enabling dynamic access control to content based on user-selected classification values, thereby reducing administrative burdens and enhancing compliance by tracking access for potential violations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If administrator-defined criteria are used for filtering information, then access control is established, but administrative overhead increases and the risk of unauthorized access increases

Engineering Contradiction:
Improveaccess controlVSAvoidadministrative overhead
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Users self-declare their permission attributes (such as employee type, department, clearance level) without administrator intervention. The system automatically uses these self-declared attributes to control access to information, eliminating the need for administrators to manually define and manage user permissions.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

Instead of administrators defining user attributes and permissions, the system inverts the approach by having users define their own attributes. Access control is then based on these user-defined attributes rather than administrator-assigned permissions.

Inventive Principle:
Principle #13The other way round (Inversion)

2Reliability

If administrator-defined criteria are used for filtering information, then access control is established, but the risk of policy violations increases when administrators are unaware of user identities or affiliations

Engineering Contradiction:
Improveaccess controlVSAvoidpolicy violation risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

Users actively participate in defining their own permission attributes, ensuring that the system has accurate information about their identities and affiliations. This self-declaration process eliminates the risk of administrators being unaware of user characteristics, as users themselves provide this information.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system implements auditing mechanisms that track and record user access based on their self-declared attributes. This feedback loop allows the system to monitor compliance and detect potential policy violations, enhancing the ability to prevent harmful access.

Inventive Principle:
Principle #23Feedback

3Device complexity

If users can self-declare permission attributes, then administrative overhead is reduced, but the risk of abuse or violation of policies increases

Engineering Contradiction:
Improveadministrative overheadVSAvoidabuse risk
Core Design Contradiction:
Device complexityVSObject-affected harmful factors

Solution Approach 1:

The system implements comprehensive auditing that tracks user access decisions based on self-declared attributes. This feedback mechanism allows the system to monitor for abnormal patterns, detect potential abuses, and maintain compliance records for review by compliance officers or administrators.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system performs preliminary validation and consistency checks on user-declared attributes before granting access. By checking attributes in advance against known criteria and patterns, the system can detect potentially abusive declarations before they result in unauthorized access.

Inventive Principle:
Principle #10Preliminary action

4Measurement precision

If dynamic filtering based on user attributes is implemented, then access accuracy is improved, but system complexity increases

Engineering Contradiction:
Improveaccess accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

Users provide their own attribute information, which the system stores and automatically applies for access control decisions. This self-service approach provides accurate user attribute data without requiring complex data collection and verification systems.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system uses simple parameter matching between user attributes and content classification requirements. By changing from complex permission management to straightforward attribute parameter comparison, the system achieves accurate access control with reduced complexity.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS9069436B1System and method for information delivery based on at least one self-declared user attribute
Publication Date: 2015.06.30 INTRALINKS INC
  • US9069436B1 patent drawing
  • US9069436B1 patent drawing
  • US9069436B1 patent drawing

AI summary

Various embodiments of the present invention are directed to providing a user the ability to self-declare one or more permission attributes about the user that form the basis for the filtering (e.g., the dynamic filtering) of current and/or future content. In this manner, access to the content may thus be governed by the self-declared permission attributes (in one example (which example is intended to be illustrative and not restrictive), the present invention may operate within a secure, tracked content delivery infrastructure).