Virtual Roles for ABAC Re-certification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In information technology systems, the Attribute-Based Access Control (ABAC) model faces challenges in re-certifying entitlements due to complex policies, leading to unnecessary, undesired, or dangerous permissions, which affects security and compliance with regulatory requirements.
Innovation Solution
The method determines virtual roles based on subject attributes by correlating access types and attributes, providing a straightforward way to review and re-certify permissions, thereby adding context to the access control process and reducing risks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If Attribute Based Access Control (ABAC) model is used to provide flexible and adaptive access control, then adaptability and versatility are improved, but device complexity and difficulty of detecting and measuring increase due to complex policies with many attributes, glue code and custom code
Solution Approach 1:
The patent introduces virtual roles as an intermediary layer between the complex ABAC policies and the re-certification process. These virtual roles aggregate multiple attributes and policies into unified, human-readable role definitions, making the system manageable without reducing its underlying adaptability. The virtual roles serve as mediators that translate complex attribute-based decisions into comprehensible authorization contexts for reviewers.
Solution Approach 2:
The patent creates virtual roles that are copies or abstractions of the complex policy structures. Instead of directly managing and reviewing the original complex ABAC policies with all their attributes and code, the system generates simplified virtual role representations that capture the essential authorization context, making re-certification feasible while preserving the full functionality of the original policies.
2Adaptability or versatility
If ABAC model is used with complex policies, then adaptability is improved, but ease of operation deteriorates as interpretation of policies becomes very difficult, if not impossible
Solution Approach 1:
Virtual roles act as intermediaries that bridge the gap between complex ABAC policies and human reviewers. They provide an accessible interface for understanding authorization contexts without requiring reviewers to interpret complex policy logic directly, thus maintaining adaptability while dramatically improving ease of operation.
Solution Approach 2:
The patent segments the complex policy evaluation into discrete virtual role assignments. Instead of presenting the entire complex policy structure for review, the system breaks it down into individual virtual roles with specific attribute combinations, making each unit manageable and interpretable while preserving the overall system's adaptability.
3Productivity
If re-certification is performed blindly without effective knowledge of authorization context in ABAC model, then productivity is improved by simplifying the review process, but reliability deteriorates leading to unnecessary, undesired or dangerous permissions
Solution Approach 1:
The patent performs preliminary analysis by automatically generating virtual roles and their associated authorization contexts before the re-certification review. This preparation work includes evaluating attribute combinations and determining relevant policies in advance, so that reviewers receive pre-processed, context-enriched information. This preliminary action maintains high productivity by automating complex analysis while improving reliability by providing reviewers with the knowledge needed to make informed decisions.
Solution Approach 2:
The system provides feedback to reviewers in the form of virtual role assignments and authorization context information. This feedback mechanism ensures that reviewers have access to relevant policy interpretations and attribute evaluations, enabling them to certify or revoke permissions with confidence. The feedback loop maintains productivity through automation while enhancing reliability through informed human judgment.
Data Source
AI summary
A solution is proposed for reviewing a control of access in an information technology system. A corresponding method comprises retrieving an indication of granted accesses to objects, being granted to subjects according to policies based on attributes. Virtual roles (each defined by one or more of the attributes) are determined according to a correlation among access types of the granted accesses and the attributes of the subjects being granted them. A computer program and a computer program product for performing the method are also proposed. Moreover, a system for implementing the method is proposed.


