User-Centric Access Control Engine for Web Services
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Users lack control over access to their user-specific information stored with web-services providers, as existing solutions like P3P are not user-friendly and do not effectively allow dynamic control over access requests.
Innovation Solution
A system and method that utilize access control lists and an access control engine to manage user-specific information, allowing users to set default preferences and dynamically grant or deny access requests based on consent, with silent negotiation for authorized requests and explicit consent for unauthorized ones through a consent user interface.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If P3P is used to standardize privacy policies, then privacy policy interpretation capability is improved, but user-friendliness and ease of operation deteriorate
Solution Approach 1:
The patent introduces an intermediary layer between the complex P3P technical standard and the end user. This intermediary translates machine-readable privacy policies into user-friendly visual representations showing what information is collected, why it is collected, and who has access to it. The intermediary enables both precise policy interpretation and ease of user understanding by bridging the gap between technical accuracy and user comprehension.
2Measurement precision
If access control lists are made comprehensive to cover all access scenarios, then access control precision is improved, but system complexity increases
Solution Approach 1:
The patent applies preliminary action by establishing default access control rules that automatically apply to common scenarios before specific access requests occur. These default rules pre-configure acceptable access patterns, reducing the need for complex ad-hoc access control decisions. When access requests are received, the system first checks against predefined defaults, only escalating to more complex evaluation when necessary, thereby maintaining precision while reducing overall system complexity.
3Adaptability or versatility
If dynamic access control is implemented to respond to each access request, then user control capability is improved, but processing time increases
Solution Approach 1:
The system performs preliminary actions by pre-evaluating access requests against default access control rules before presenting them to users. Common access patterns are automatically approved or denied based on pre-configured policies, reserving user intervention only for non-routine cases. This approach maintains dynamic adaptability for exceptional situations while minimizing processing time for standard operations through automated preliminary decisions.
Solution Approach 2:
The patent implements partial action by applying automated access control decisions to the majority of routine access requests without full user intervention, while reserving complete dynamic control for exceptional cases. This partial automation of the access control process reduces overall processing time while maintaining user control capability where it is most needed, avoiding the time cost of full dynamic evaluation for every single access request.
Data Source
AI summary
In a network computing environment, a user-centric system and method for controlling access to user-specific information maintained in association with a web-services service. When a web-services client desires access to the user-specific information, the client sends a request. The request identifies the reasons/intentions for accessing the desired information. The request is compared to the user's existing access permissions. If there is no existing access permission, the request is compared to the user's default preferences. If the default preferences permit the requested access, an access rule is created dynamically and the client's request is filled, without interrupting the user. If the default preferences do not permit the request to be filled, a consent user interface may be invoked. The consent user interface presents the user with one or more consent options, thereby permitting the user to control whether the client will be given access to the user-specific information.


