Unified Access Control for Electronic Archives

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current electronic records archives systems lack the flexibility and scalability to manage and preserve the authenticity of electronic records over an indefinite period, especially in a manner that is obsolescence-proof, and fail to provide comprehensive access control across security domains.

Innovation Solution

The implementation of a system that combines Mandatory Access Controls, Discretionary Access Controls, Role-Based Access Controls, and Content-Based Access Controls, along with advanced access control mechanisms, to provide a flexible and extensible access control mechanism that allows for secure, scalable, and obsolescence-proof management and preservation of electronic records across security domains.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If classical OS level access controls (MAC and DAC) are used, then access security is provided, but flexibility for modern automated information systems is insufficient

Engineering Contradiction:
Improveaccess securityVSAvoidflexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent combines multiple access control methodologies (Mandatory Access Control, Discretionary Access Control, Role-Based Access Control, and Content-Based Access Control) into a unified framework. This integration allows the system to leverage the security strengths of MAC and DAC while incorporating the flexibility of RBAC and the precision of CBAC, thereby resolving the contradiction between security and adaptability.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The access control system is designed to be universal and multi-functional, supporting various access control models within a single framework. The system can operate in different modes (MAC, DAC, RBAC, CBAC) and can be configured to meet diverse security requirements while maintaining flexibility for modern automated information systems.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If Role Based Access Control is implemented, then improvement over DAC is achieved, but flexibility needed by modern AISs is still insufficient

Engineering Contradiction:
Improveaccess control effectivenessVSAvoidflexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent merges Role-Based Access Control with Content-Based Access Control and other models. RBAC provides the structural framework for role-based permissions, while CBAC adds content-specific rules that can dynamically adjust access based on record attributes, workflow state, and user context, thereby enhancing the flexibility that RBAC alone cannot provide.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system introduces dynamic elements to RBAC by incorporating content-based rules that can change access permissions based on varying conditions such as workflow state, time, and record metadata. This makes the access control system adaptable to changing requirements in modern automated information systems while maintaining the organizational structure of role-based control.

Inventive Principle:
Principle #15Dynamics

3Device complexity

If access control is restricted to single security domain, then implementation is simpler, but ability to operate across Federations is limited

Engineering Contradiction:
Improveimplementation complexityVSAvoidcross-Federation capability
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The access control system is designed with universal capabilities that enable it to function across multiple security domains and Federations. The unified framework can translate and enforce access control policies across different domains, supporting cross-Federation operations while maintaining a consistent implementation approach that does not significantly increase complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Reliability

If traditional access control methods are used, then basic security is provided, but obsolescence-proof preservation of electronic records is not achieved

Engineering Contradiction:
Improvebasic securityVSAvoidpreservation duration
Core Design Contradiction:
ReliabilityVSDuration of action of stationary object

Solution Approach 1:

The system implements dynamic access control policies that can adapt to changing security requirements and technological environments over time. Content-based rules can be updated without changing the underlying system architecture, allowing the access control mechanism to remain effective and secure throughout the indefinite preservation period of electronic records, making it obsolescence-proof.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS8726351B2Systems and methods for controlling access to electronic records in an archives system
Publication Date: 2014.05.13 FENESTRA TECHNOLOGIES CORP
  • US8726351B2 patent drawing
  • US8726351B2 patent drawing
  • US8726351B2 patent drawing

AI summary

Systems and/or methods for controlling access to a plurality of records and/or documentary materials to be persisted in an electronic archives system are provided. The plurality of records and/or documentary material and all preserved information may be stored and accessed on the basis of user and/or object attributes. The user attributes include group affiliation, ownership, and state (e.g., workflow step and time of day). The object attributes include group affiliation, business role, clearance or access level, and network address from which access is requested. Access to the plurality of records and/or documentary material can be obtained both from within a single security domain as well as across more than one security domain.