Universal Authorization Language for Cross-Platform Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Implementing security authorization requirements across diverse access control mechanisms in large-scale computer systems is challenging due to the difficulty in integrating and enforcing coherent security policies across functionally different environments and applications.
Innovation Solution
A method and apparatus that model security authorization policies using Unified Modeling Language (UML) and transform them into a Universal Authorization Language (UAL) policy set, which is then adapted and implemented across various target systems using environment-specific adapters, ensuring consistent access control across disparate access control systems.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If security authorization requirements are implemented across diverse access control mechanisms, then security coverage and protection scope are improved, but system complexity and integration difficulty increase
Solution Approach 1:
The patent implements a universal security policy framework that can operate across multiple dissimilar access control platforms (ACL-based, RBAC-based, policy-based systems). The framework provides multi-functionality by adapting to different target systems through platform-specific adapters while maintaining a common policy representation language, thereby extending security coverage without proportionally increasing integration complexity
Solution Approach 2:
The patent introduces an intermediary security policy framework that mediates between security requirements and diverse access control mechanisms. This framework includes a common policy representation language and adaptation mechanisms that translate security policies into platform-specific formats, reducing integration difficulty while maintaining comprehensive security coverage
2Stability of the object's composition
If coherent security policies are enforced across functionally different environments, then security consistency is improved, but policy integration difficulty and implementation complexity increase
Solution Approach 1:
The patent employs a homogeneous common policy representation language that provides consistent security policy structure across functionally different environments. This unified representation format enables coherent policy expression while simplifying integration by providing a standardized intermediate form that can be systematically adapted to various target systems
Solution Approach 2:
The security policy framework achieves universality by designing a common policy representation that can be consistently applied across different functional environments (file systems, database systems, application servers). The framework includes adaptation mechanisms that maintain policy consistency while targeting specific platform requirements, thereby enforcing coherent security policies without proportionally increasing integration complexity
3Adaptability or versatility
If access control policies are adapted to multiple target systems, then adaptability and coverage are improved, but policy representation complexity and adaptation effort increase
Solution Approach 1:
The patent segments the policy adaptation process into distinct components: a common policy representation language that captures security requirements in a platform-independent manner, and platform-specific adapters that handle the translation to target systems. This segmentation allows the core policy logic to remain simple while distributing the adaptation complexity across multiple independent modules, thereby improving platform compatibility without proportionally increasing overall policy representation complexity
Data Source
AI summary
A method of implementing access control requirements to control access to a plurality of system resources. The requirements are modeled as contents of security policies. The security policy contents are integrated into a policy set. Representations of the integrated policy set are generated, each representation corresponding to a target system that controls access to the resources. The policy set representation(s) are integrated with the corresponding target system(s) to implement the policy set. This method makes it possible to implement high-level security requirements correctly and consistently across systems of a system-of-systems (SoS) and/or distributed system.


