Unified Access Control for Electronic Archives
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current electronic records archives systems lack the flexibility and scalability to manage and preserve the authenticity of electronic records over an indefinite period, especially in a manner that is obsolescence-proof, and fail to provide comprehensive access control across security domains.
Innovation Solution
The implementation of a system that combines Mandatory Access Controls, Discretionary Access Controls, Role-Based Access Controls, and Content-Based Access Controls, along with advanced access control mechanisms, to provide a flexible and extensible access control mechanism that allows for secure, scalable, and obsolescence-proof management and preservation of electronic records across security domains.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If classical OS level access controls (MAC and DAC) are used, then access security is provided, but flexibility for modern automated information systems is insufficient
Solution Approach 1:
The patent combines multiple access control methodologies (Mandatory Access Control, Discretionary Access Control, Role-Based Access Control, and Content-Based Access Control) into a unified framework. This integration allows the system to leverage the security strengths of MAC and DAC while incorporating the flexibility of RBAC and the precision of CBAC, thereby resolving the contradiction between security and adaptability.
Solution Approach 2:
The access control system is designed to be universal and multi-functional, supporting various access control models within a single framework. The system can operate in different modes (MAC, DAC, RBAC, CBAC) and can be configured to meet diverse security requirements while maintaining flexibility for modern automated information systems.
2Reliability
If Role Based Access Control is implemented, then improvement over DAC is achieved, but flexibility needed by modern AISs is still insufficient
Solution Approach 1:
The patent merges Role-Based Access Control with Content-Based Access Control and other models. RBAC provides the structural framework for role-based permissions, while CBAC adds content-specific rules that can dynamically adjust access based on record attributes, workflow state, and user context, thereby enhancing the flexibility that RBAC alone cannot provide.
Solution Approach 2:
The system introduces dynamic elements to RBAC by incorporating content-based rules that can change access permissions based on varying conditions such as workflow state, time, and record metadata. This makes the access control system adaptable to changing requirements in modern automated information systems while maintaining the organizational structure of role-based control.
3Device complexity
If access control is restricted to single security domain, then implementation is simpler, but ability to operate across Federations is limited
Solution Approach 1:
The access control system is designed with universal capabilities that enable it to function across multiple security domains and Federations. The unified framework can translate and enforce access control policies across different domains, supporting cross-Federation operations while maintaining a consistent implementation approach that does not significantly increase complexity.
4Reliability
If traditional access control methods are used, then basic security is provided, but obsolescence-proof preservation of electronic records is not achieved
Solution Approach 1:
The system implements dynamic access control policies that can adapt to changing security requirements and technological environments over time. Content-based rules can be updated without changing the underlying system architecture, allowing the access control mechanism to remain effective and secure throughout the indefinite preservation period of electronic records, making it obsolescence-proof.
Data Source
AI summary
Systems and/or methods for controlling access to a plurality of records and/or documentary materials to be persisted in an electronic archives system are provided. The plurality of records and/or documentary material and all preserved information may be stored and accessed on the basis of user and/or object attributes. The user attributes include group affiliation, ownership, and state (e.g., workflow step and time of day). The object attributes include group affiliation, business role, clearance or access level, and network address from which access is requested. Access to the plurality of records and/or documentary material can be obtained both from within a single security domain as well as across more than one security domain.


