User Visibility Segmentation for Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing digital rights management systems lack effective mechanisms to restrict content item permissions to only authorized users and groups, potentially leading to inadvertent or malicious access to sensitive content.

Innovation Solution

A system that allows administrators to define and assign content permission policies, where users and groups are selectively made visible for permission management, using a policy administration application, user/group administration application, and policy server application to enforce access controls.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If administrators can view and assign permissions to all users and groups, then ease of operation is improved, but security is worsened due to potential inadvertent or malicious access to sensitive content

Engineering Contradiction:
Improveease of operationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system segments users into different visibility groups (e.g., administrators, authors, editors) with different levels of access to user and group listings. Each group can only view and assign permissions to users within their designated scope, preventing inadvertent or malicious access to sensitive content while maintaining operational ease within each segment.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Different users are granted different qualities of access based on their role. Administrators can view all users and groups, while authors can only view users they are directly associated with, and editors have limited visibility. This local differentiation of access quality ensures security without unnecessarily complicating the operation for each user tier.

Inventive Principle:
Principle #3Local quality

2Adaptability or versatility

If the system provides comprehensive user and group listing for permission assignment, then adaptability is improved, but device complexity increases due to multiple applications and policies to manage

Engineering Contradiction:
ImproveadaptabilityVSAvoiddevice complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The policy administration application serves multiple functions: it manages content item permissions, controls user visibility, enforces access policies, and coordinates with the policy server. This multi-functionality reduces the need for separate complex systems while maintaining adaptability across different permission scenarios.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The policy server acts as an intermediary between the policy administration application and the content items. It receives permission requests, evaluates them against defined policies, and enforces access controls. This intermediary layer simplifies the overall system architecture by centralizing the complexity of policy evaluation and enforcement.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8712981B2Mechanism for visible users and groups
Publication Date: 2014.04.29 ADOBE INC
  • US8712981B2 patent drawing
  • US8712981B2 patent drawing
  • US8712981B2 patent drawing

AI summary

Various embodiments described herein provide systems, methods, software, and data structures to allow or prevent viewing of users and groups of users by other users and groups of users. Some such embodiments include retrieving a listing of members from a member database, defining a first subset of one or more members selected from the retrieved member listing, and designating the first member subset as visible to a second subset of one or more members when a member of the second member subset retrieves a member listing.