Universal Access Control via Distributed Policy Enforcement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current access control methods, such as Unix permissions and Access Control Lists (ACLs), lack flexibility and universality, failing to effectively manage access to files and non-file system objects, and do not provide centralized control over application program access or location-specific permissions.

Innovation Solution

A method and apparatus for controlling document access and application usage using centrally managed rules, where a rule server distributes policies to client systems and servers, allowing policy enforcers to evaluate and enforce access control decisions autonomously, including obligation and remediation operations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If Unix permissions or ACLs are used for access control, then file system access can be managed, but the system lacks flexibility and cannot effectively manage access to non-file system objects or provide centralized control

Engineering Contradiction:
Improveaccess control scopeVSAvoidcontrol system architecture
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements a universal access control system using XACML policies that can manage permissions across multiple object types including files, emails, web pages, and other non-file system objects. The policy enforcement point evaluates centralized policies locally, providing unified access control for diverse resources without requiring separate mechanisms for each object type.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent introduces a policy enforcement point as an intermediary component that receives centralized XACML policies from the policy decision point and executes them locally. This mediator enables distributed policy evaluation, allowing the system to maintain centralized policy management while achieving flexible local enforcement across different system components and locations.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If access control policies are centralized on a server, then universal management is achieved, but the system cannot enforce policies when disconnected from the central server

Engineering Contradiction:
Improvepolicy enforcement capabilityVSAvoidaccess control continuity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent implements preliminary action by distributing XACML policies from the central policy decision point to local policy enforcement points in advance. These policies are cached and stored locally on client systems, enabling the enforcement points to evaluate and enforce access control decisions autonomously even when disconnected from the central server, thus ensuring policy enforcement continuity.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If traditional ACLs are used, then file access control is provided, but location-specific permissions and application program control are not available

Engineering Contradiction:
Improvepermission granularityVSAvoidpolicy management system
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements local quality by enabling location-specific and context-specific access control through XACML policies. The policy enforcement point evaluates policies based on local conditions such as user location, application program identity, and resource type, allowing different permission granularities for different contexts while maintaining a unified policy framework.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS10104125B2Enforcing universal access control in an information management system
Publication Date: 2018.10.16 NEXTLABS INC
  • US10104125B2 patent drawing
  • US10104125B2 patent drawing
  • US10104125B2 patent drawing

AI summary

A method and apparatus for controlling document access and application usage using centrally managed rules. The rules are stored and manipulated in a central rule database via a rule server. Policy enforcers are installed on client systems and/or on servers and perform document access and application usage control for both direct user document accesses and application usage, and application program document accesses by evaluating the rules sent to the policy enforcer. The rule server decides which rules are required by each policy enforcer. A policy enforcer can also perform obligation and remediation operations as a part of rule evaluation. Policy enforcers on client systems and servers can operate autonomously, evaluating policies that have been received, when communications have been discontinued with the rule server.