Universal Authorization Language for Cross-Platform Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Implementing security authorization requirements across diverse access control mechanisms in large-scale computer systems is challenging due to the difficulty in integrating and enforcing coherent security policies across functionally different environments and applications.

Innovation Solution

A method and apparatus that model security authorization policies using Unified Modeling Language (UML) and transform them into a Universal Authorization Language (UAL) policy set, which is then adapted and implemented across various target systems using environment-specific adapters, ensuring consistent access control across disparate access control systems.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security authorization requirements are implemented across diverse access control mechanisms, then security coverage and protection scope are improved, but system complexity and integration difficulty increase

Engineering Contradiction:
Improvesecurity coverageVSAvoidsystem integration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal security policy framework that can operate across multiple dissimilar access control platforms (ACL-based, RBAC-based, policy-based systems). The framework provides multi-functionality by adapting to different target systems through platform-specific adapters while maintaining a common policy representation language, thereby extending security coverage without proportionally increasing integration complexity

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent introduces an intermediary security policy framework that mediates between security requirements and diverse access control mechanisms. This framework includes a common policy representation language and adaptation mechanisms that translate security policies into platform-specific formats, reducing integration difficulty while maintaining comprehensive security coverage

Inventive Principle:
Principle #24Intermediary (Mediator)

2Stability of the object's composition

If coherent security policies are enforced across functionally different environments, then security consistency is improved, but policy integration difficulty and implementation complexity increase

Engineering Contradiction:
Improvesecurity policy consistencyVSAvoidpolicy integration complexity
Core Design Contradiction:
Stability of the object's compositionVSDevice complexity

Solution Approach 1:

The patent employs a homogeneous common policy representation language that provides consistent security policy structure across functionally different environments. This unified representation format enables coherent policy expression while simplifying integration by providing a standardized intermediate form that can be systematically adapted to various target systems

Inventive Principle:
Principle #33Homogeneity

Solution Approach 2:

The security policy framework achieves universality by designing a common policy representation that can be consistently applied across different functional environments (file systems, database systems, application servers). The framework includes adaptation mechanisms that maintain policy consistency while targeting specific platform requirements, thereby enforcing coherent security policies without proportionally increasing integration complexity

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Adaptability or versatility

If access control policies are adapted to multiple target systems, then adaptability and coverage are improved, but policy representation complexity and adaptation effort increase

Engineering Contradiction:
Improveplatform compatibilityVSAvoidpolicy representation complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the policy adaptation process into distinct components: a common policy representation language that captures security requirements in a platform-independent manner, and platform-specific adapters that handle the translation to target systems. This segmentation allows the core policy logic to remain simple while distributing the adaptation complexity across multiple independent modules, thereby improving platform compatibility without proportionally increasing overall policy representation complexity

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS8056114B2Implementing access control policies across dissimilar access control platforms
Publication Date: 2011.11.08 THE BOEING CO
  • US8056114B2 patent drawing
  • US8056114B2 patent drawing
  • US8056114B2 patent drawing

AI summary

A method of implementing access control requirements to control access to a plurality of system resources. The requirements are modeled as contents of security policies. The security policy contents are integrated into a policy set. Representations of the integrated policy set are generated, each representation corresponding to a target system that controls access to the resources. The policy set representation(s) are integrated with the corresponding target system(s) to implement the policy set. This method makes it possible to implement high-level security requirements correctly and consistently across systems of a system-of-systems (SoS) and/or distributed system.