Unified Management Policy Expression for Identity Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current identity management systems treat access control and events as separate entities, leading to fragmented management policies that are difficult to unify and enforce consistently.

Innovation Solution

A unified management policy expression is introduced that combines access control and event/workflow definitions into a single concept, allowing for a single definition of conditions to grant permissions and trigger responses, enabling a consistent mechanism for determining access permissions and required events.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If access control and events are treated as separate entities, then each can be defined and managed independently, but the management policy becomes fragmented and difficult to enforce consistently

Engineering Contradiction:
ImproveIndependent definition capabilityVSAvoidPolicy management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent merges access control rules and event workflows into a unified management policy structure. Both access control information (defining permissions) and event workflows (defining responses) are stored together in the same data structure, allowing consistent enforcement of management policies while maintaining the ability to define each component independently within the unified framework.

Inventive Principle:
Principle #5Merging (Combining)

2Ease of manufacture

If separate object definitions are used for access control and events, then each component can be optimized independently, but the overall system becomes more complex and harder to manage

Engineering Contradiction:
ImproveComponent optimizationVSAvoidSystem structure complexity
Core Design Contradiction:
Ease of manufactureVSDevice complexity

Solution Approach 1:

The unified management policy structure serves multiple functions simultaneously: it stores access control information, defines event workflows, and provides the framework for consistent enforcement. This multi-functional approach allows the system to maintain component optimization capabilities while reducing overall structural complexity through a single versatile data structure.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Ease of manufacture

If access control and events are separated, then implementation is simpler initially, but enforcement consistency and security are compromised

Engineering Contradiction:
ImproveInitial implementation simplicityVSAvoidEnforcement consistency
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

By combining access control and event workflows into a unified management policy, the system ensures consistent enforcement of security policies. The unified structure allows simultaneous evaluation of both access permissions and event responses, eliminating the enforcement inconsistencies that arise when separate definitions are used.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS8353005B2Unified management policy
Publication Date: 2013.01.08 MICROSOFT TECHNOLOGY LICENSING LLC
  • US8353005B2 patent drawing
  • US8353005B2 patent drawing
  • US8353005B2 patent drawing

AI summary

Defining a unified access management policy expression that unifies access control policy with events or workflows. Unified management policy information is stored. The unified management policy information defines permissions for access to resources together with events or workflows. A request is received to execute the one or more operations on one or more objects. The requested operation is verified against the unified management rules. Verifying includes performing a single retrieval, retrieving both the access control information and the events or workflows and calculating the applicability of the rule to the conditions represented by the request. Matching rules are applied, access control decisions performed and associated workflows are executed.