Universal Access Control via Distributed Policy Enforcement
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current access control methods, such as Unix permissions and Access Control Lists (ACLs), lack flexibility and universality, failing to effectively manage access to files and non-file system objects, and do not provide centralized control over application program access or location-specific permissions.
Innovation Solution
A method and apparatus for controlling document access and application usage using centrally managed rules, where a rule server distributes policies to client systems and servers, allowing policy enforcers to evaluate and enforce access control decisions autonomously, including obligation and remediation operations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If Unix permissions or ACLs are used for access control, then file system access can be managed, but the system lacks flexibility and cannot effectively manage access to non-file system objects or provide centralized control
Solution Approach 1:
The patent implements a universal access control system using XACML policies that can manage permissions across multiple object types including files, emails, web pages, and other non-file system objects. The policy enforcement point evaluates centralized policies locally, providing unified access control for diverse resources without requiring separate mechanisms for each object type.
Solution Approach 2:
The patent introduces a policy enforcement point as an intermediary component that receives centralized XACML policies from the policy decision point and executes them locally. This mediator enables distributed policy evaluation, allowing the system to maintain centralized policy management while achieving flexible local enforcement across different system components and locations.
2Adaptability or versatility
If access control policies are centralized on a server, then universal management is achieved, but the system cannot enforce policies when disconnected from the central server
Solution Approach 1:
The patent implements preliminary action by distributing XACML policies from the central policy decision point to local policy enforcement points in advance. These policies are cached and stored locally on client systems, enabling the enforcement points to evaluate and enforce access control decisions autonomously even when disconnected from the central server, thus ensuring policy enforcement continuity.
3Adaptability or versatility
If traditional ACLs are used, then file access control is provided, but location-specific permissions and application program control are not available
Solution Approach 1:
The patent implements local quality by enabling location-specific and context-specific access control through XACML policies. The policy enforcement point evaluates policies based on local conditions such as user location, application program identity, and resource type, allowing different permission granularities for different contexts while maintaining a unified policy framework.
Data Source
AI summary
A method and apparatus for controlling document access and application usage using centrally managed rules. The rules are stored and manipulated in a central rule database via a rule server. Policy enforcers are installed on client systems and/or on servers and perform document access and application usage control for both direct user document accesses and application usage, and application program document accesses by evaluating the rules sent to the policy enforcer. The rule server decides which rules are required by each policy enforcer. A policy enforcer can also perform obligation and remediation operations as a part of rule evaluation. Policy enforcers on client systems and servers can operate autonomously, evaluating policies that have been received, when communications have been discontinued with the rule server.


