User-Centric Access Control Engine for Web Services

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users lack control over access to their user-specific information stored with web-services providers, as existing solutions like P3P are not user-friendly and do not effectively allow dynamic control over access requests.

Innovation Solution

A system and method that utilize access control lists and an access control engine to manage user-specific information, allowing users to set default preferences and dynamically grant or deny access requests based on consent, with silent negotiation for authorized requests and explicit consent for unauthorized ones through a consent user interface.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If P3P is used to standardize privacy policies, then privacy policy interpretation capability is improved, but user-friendliness and ease of operation deteriorate

Engineering Contradiction:
Improveprivacy policy interpretation capabilityVSAvoiduser-friendliness
Core Design Contradiction:
Measurement precisionVSEase of operation

Solution Approach 1:

The patent introduces an intermediary layer between the complex P3P technical standard and the end user. This intermediary translates machine-readable privacy policies into user-friendly visual representations showing what information is collected, why it is collected, and who has access to it. The intermediary enables both precise policy interpretation and ease of user understanding by bridging the gap between technical accuracy and user comprehension.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If access control lists are made comprehensive to cover all access scenarios, then access control precision is improved, but system complexity increases

Engineering Contradiction:
Improveaccess control precisionVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by establishing default access control rules that automatically apply to common scenarios before specific access requests occur. These default rules pre-configure acceptable access patterns, reducing the need for complex ad-hoc access control decisions. When access requests are received, the system first checks against predefined defaults, only escalating to more complex evaluation when necessary, thereby maintaining precision while reducing overall system complexity.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If dynamic access control is implemented to respond to each access request, then user control capability is improved, but processing time increases

Engineering Contradiction:
Improveuser control capabilityVSAvoidprocessing time
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-evaluating access requests against default access control rules before presenting them to users. Common access patterns are automatically approved or denied based on pre-configured policies, reserving user intervention only for non-routine cases. This approach maintains dynamic adaptability for exceptional situations while minimizing processing time for standard operations through automated preliminary decisions.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements partial action by applying automated access control decisions to the majority of routine access requests without full user intervention, while reserving complete dynamic control for exceptional cases. This partial automation of the access control process reduces overall processing time while maintaining user control capability where it is most needed, avoiding the time cost of full dynamic evaluation for every single access request.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS7912971B1System and method for user-centric authorization to access user-specific information
Publication Date: 2011.03.22 MICROSOFT TECHNOLOGY LICENSING LLC
  • US7912971B1 patent drawing
  • US7912971B1 patent drawing
  • US7912971B1 patent drawing

AI summary

In a network computing environment, a user-centric system and method for controlling access to user-specific information maintained in association with a web-services service. When a web-services client desires access to the user-specific information, the client sends a request. The request identifies the reasons/intentions for accessing the desired information. The request is compared to the user's existing access permissions. If there is no existing access permission, the request is compared to the user's default preferences. If the default preferences permit the requested access, an access rule is created dynamically and the client's request is filled, without interrupting the user. If the default preferences do not permit the request to be filled, a consent user interface may be invoked. The consent user interface presents the user with one or more consent options, thereby permitting the user to control whether the client will be given access to the user-specific information.