XML Policy Server for Cross-System Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current access control systems, such as Unix permissions and access control lists, lack flexibility and universality, failing to effectively manage access to information across different file systems, applications, and organizations, especially in managing non-file system objects like emails and Web pages, and do not enforce ethical walls between groups.

Innovation Solution

An information management system with a policy server that enforces rules to manage access to documents, emails, and applications, allowing for flexible control of user and application access across different groups and organizations, using policy enforcers installed on workstations and document servers to intercept and enforce access policies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If traditional access control systems (Unix permissions or ACL) are used, then implementation is simple, but flexibility and universality are limited

Engineering Contradiction:
Improveflexibility and universality of access controlVSAvoidcomplexity of access control system
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements a universal access control system using XML-based policy files that can manage permissions across multiple file systems, applications, and organizational structures. The system uses a standardized policy language that works uniformly for different types of objects (files, emails, web pages) and different access control scenarios, replacing the need for separate control mechanisms for each context.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent introduces an intermediary policy enforcement mechanism that sits between users and resources. This intermediary layer uses XML policy files to mediate access decisions, allowing complex access control logic to be implemented without modifying the underlying operating system or file systems. The policy server acts as a mediator that interprets and enforces access policies across the entire system.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If access control lists are used for specific users and groups, then file access control is improved, but control over non-file system objects and application programs is not achieved

Engineering Contradiction:
Improvescope of access control coverageVSAvoidcomplexity of policy management system
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent extends access control beyond traditional file systems to cover emails, web pages, and other non-file system objects. The XML-based policy language provides a universal framework that can define access rules for any type of object or application program, making the system adaptable to diverse access control needs without requiring separate mechanisms for each object type.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Ease of operation

If centralized access control is implemented, then policy management is simplified, but system performance and user autonomy may be reduced

Engineering Contradiction:
Improveease of policy managementVSAvoidsystem performance and user autonomy
Core Design Contradiction:
Ease of operationVSProductivity

Solution Approach 1:

The patent segments the access control system into modular XML policy files that can be independently managed, stored, and enforced. Each policy file can be targeted to specific users, groups, or resources, allowing fine-grained control without requiring a monolithic centralized authority. This segmentation enables parallel policy evaluation and reduces bottlenecks in the access control process.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS10223366B2Preventing conflicts of interests between two or more groups
Publication Date: 2019.03.05 NEXTLABS INC
  • US10223366B2 patent drawing
  • US10223366B2 patent drawing
  • US10223366B2 patent drawing

AI summary

To prevent conflicts of interest, an information management system is used to make sure two or more groups are kept apart so that information does not circulate freely between these groups. The system has policies to implement an “ethical wall” to separate users or groups of users. The user or groups of user may be organized in any arbitrary way, and may be in the same organization or different organizations. The two groups (or two or more users) will not be able to access information belonging to the other, and users in one group may not be able to pass information to the other group. The system may manage access to documents, e-mail, files, and other forms of information.