Unified Management Policy Expression for Identity Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current identity management systems treat access control and events as separate entities, leading to fragmented management policies that are difficult to unify and enforce consistently.
Innovation Solution
A unified management policy expression is introduced that combines access control and event/workflow definitions into a single concept, allowing for a single definition of conditions to grant permissions and trigger responses, enabling a consistent mechanism for determining access permissions and required events.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If access control and events are treated as separate entities, then each can be defined and managed independently, but the management policy becomes fragmented and difficult to enforce consistently
Solution Approach 1:
The patent merges access control rules and event workflows into a unified management policy structure. Both access control information (defining permissions) and event workflows (defining responses) are stored together in the same data structure, allowing consistent enforcement of management policies while maintaining the ability to define each component independently within the unified framework.
2Ease of manufacture
If separate object definitions are used for access control and events, then each component can be optimized independently, but the overall system becomes more complex and harder to manage
Solution Approach 1:
The unified management policy structure serves multiple functions simultaneously: it stores access control information, defines event workflows, and provides the framework for consistent enforcement. This multi-functional approach allows the system to maintain component optimization capabilities while reducing overall structural complexity through a single versatile data structure.
3Ease of manufacture
If access control and events are separated, then implementation is simpler initially, but enforcement consistency and security are compromised
Solution Approach 1:
By combining access control and event workflows into a unified management policy, the system ensures consistent enforcement of security policies. The unified structure allows simultaneous evaluation of both access permissions and event responses, eliminating the enforcement inconsistencies that arise when separate definitions are used.
Data Source
AI summary
Defining a unified access management policy expression that unifies access control policy with events or workflows. Unified management policy information is stored. The unified management policy information defines permissions for access to resources together with events or workflows. A request is received to execute the one or more operations on one or more objects. The requested operation is verified against the unified management rules. Verifying includes performing a single retrieval, retrieving both the access control information and the events or workflows and calculating the applicability of the rule to the conditions represented by the request. Matching rules are applied, access control decisions performed and associated workflows are executed.


