User Access Policy Segmentation for Content Rendering

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing access control systems in content distribution systems rely on predefined access policies, which may not adequately address misbehavior by applications that comply with initial access controls, and do not provide sufficient user control over access to resources, especially for untrusted or unknown organizations.

Innovation Solution

Implementing a user access policy that restricts access to resources based on additional trust data, allowing selective access according to the organization's access policy, with the option to adjust user preferences and trust levels, including a remote database for maintaining and updating trust data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a predefined access policy is used to control application access to resources, then access control is established for compliant applications, but the system cannot adequately address misbehavior by applications that comply with initial access controls

Engineering Contradiction:
Improveaccess control effectivenessVSAvoiduser control flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The access control system is segmented into two distinct layers: organization-level access policies and user-level access policies. The organization policy defines baseline access rights for applications, while the user policy provides an additional layer of control that users can customize. This segmentation allows the system to maintain reliability through organized policy management while gaining adaptability through user-specific policy configurations.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

User access policies are established in advance with default settings before users need to make access decisions. The system pre-configures trusted and untrusted organization lists, and default allow/deny rules, so that when applications request access, the evaluation can proceed efficiently without requiring users to make decisions from scratch each time. This preliminary action maintains reliability through pre-established security boundaries while enabling adaptability through user-customizable defaults.

Inventive Principle:
Principle #10Preliminary action

2Ease of manufacture

If access control is based solely on organization compliance with access policy format, then certified applications can access resources, but users cannot selectively restrict access from untrusted organizations

Engineering Contradiction:
Improveaccess control implementationVSAvoiduntrusted organization access
Core Design Contradiction:
Ease of manufactureVSObject-affected harmful factors

Solution Approach 1:

The system segments organizations into trusted and untrusted categories based on user-defined criteria. This segmentation enables users to apply different access control rules to different organizations, allowing compliant applications from untrusted organizations to be restricted while maintaining ease of implementation through automated policy evaluation based on organizational trust status.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The user access policy acts as an intermediary layer between the organization's access policy and the actual resource access. Even when an organization complies with the predefined access policy format, the intermediary user policy can selectively block or allow access based on trust relationships. This intermediary mechanism maintains ease of implementation by building upon existing policy infrastructure while protecting against harmful factors from untrusted organizations.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Object-affected harmful factors

If user access policy restricts all organization applications by default, then protection against untrusted organizations is provided, but trusted organizations may be incorrectly blocked

Engineering Contradiction:
Improveprotection from untrusted organizationsVSAvoidresource access convenience
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The system performs preliminary classification of organizations into trusted and untrusted lists before access decisions are made. Organizations are pre-evaluated and categorized based on user-defined trust criteria, so that when applications from these organizations request access, the system can quickly determine whether to apply restrictive or permissive rules. This preliminary action provides protection from untrusted organizations while maintaining ease of operation for trusted ones.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The user access policy is dynamic and can be adjusted based on trust relationships. The system adapts its access control behavior by applying different default rules to trusted versus untrusted organizations, rather than using a static one-size-fits-all approach. This dynamics enables the system to provide strong protection against untrusted organizations while maintaining convenient access for trusted organizations, with the ability to reclassify organizations as trust relationships change.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS9202045B2System for managing access control
Publication Date: 2015.12.01 KONINKLIJKE PHILIPS NV
  • US9202045B2 patent drawing
  • US9202045B2 patent drawing
  • US9202045B2 patent drawing

AI summary

A content distribution system (300) has access control according to a predefined data access format. The system has organizations (32) for providing content data and related meta data on record carriers (34), and a rendering device (39), and applications for manipulating the content data and related meta data. An access policy for the organization is set according to the predefined data access format, and has access parameters for controlling access to resources of the rendering device and to said content data and related meta data. An organization application (35) complying with the access policy of the organization for accessing said data is executed while accessing the resources of the rendering device according to the access policy of the organization. According to the invention a user access policy is maintained that restricts, for the organization application, access to the resources of the rendering device relative to the access policy of the organization. The user access policy is adjusted based on additional trust data for selectively allowing the organization application to access the resources according to the access policy of the organization. Hence the user controls the access that applications have to resources of the rendering device.