Zone-Based Project Access Through Proxy Mediation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing access control systems for computing resources in project environments are cumbersome and prone to data security breaches due to user-focused permissions, leading to improper access and data sharing, especially in multi-project and multi-application scenarios.

Innovation Solution

A system that generates zones with defined access rights for datasets and tools, using a proxy service to manage access policies dynamically, allowing rapid adjustments and masking policies to prevent data misuse, while supporting interoperability across various applications and devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If user-focused permission levels are used for access control, then access management is simplified, but data security deteriorates due to improper access and data sharing

Engineering Contradiction:
Improveaccess management simplicityVSAvoiddata security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments access control from user-focused permissions to zone-focused permissions. Instead of granting permissions to users, the system creates zones with specific access rights and assigns devices to zones. This segmentation isolates access control logic, preventing users from accessing data outside their assigned zones even if they have high permission levels, thereby resolving the contradiction between operational simplicity and data security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a proxy service as an intermediary between devices and computing resources. The proxy service mediates all access requests by evaluating zone assignments and access rights policies before granting access. This intermediary layer ensures that even though users have permission levels, their actual access is controlled and limited to authorized zones, preventing data sharing violations while maintaining ease of operation.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Speed

If high permission levels are granted to users, then access speed is improved, but data privacy deteriorates due to inadvertent data sharing

Engineering Contradiction:
Improveaccess speedVSAvoiddata privacy
Core Design Contradiction:
SpeedVSLoss of information

Solution Approach 1:

The system segments access rights at the zone level rather than user level. Each zone has defined access rights that specify exactly which computing resources can be accessed. When a device requests access, the system quickly evaluates the zone assignment and grants or denies access based on pre-defined rights, maintaining fast access speeds while preventing data privacy violations through strict zone boundaries.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements dynamic access control where zone assignments and access rights can be changed without affecting individual users. The system dynamically evaluates access requests against current zone policies, allowing access speed to be maintained through efficient zone-based evaluation while adapting data privacy protection to changing requirements without manual permission adjustments.

Inventive Principle:
Principle #15Dynamics

3Reliability

If comprehensive access control policies are implemented, then data security is improved, but administrative complexity increases

Engineering Contradiction:
Improvedata securityVSAvoidadministration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments administration complexity by separating zone management from user management. Administrators create zones with specific access rights and assign devices to zones, rather than managing individual user permissions across multiple resources. This segmentation simplifies administration while maintaining comprehensive security, as zone-based policies automatically apply to all devices in the zone without requiring individual user permission configurations.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The proxy service provides universal access control functionality that works across multiple computing resources and devices. A single zone assignment and access right configuration applies consistently across all resources, eliminating the need for separate access control policies for each resource type. This multi-functionality reduces administrative complexity while maintaining robust data security through unified zone-based control.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Loss of information

If zone-based access control is implemented, then data privacy is improved through masking policies, but system complexity increases

Engineering Contradiction:
Improvedata privacyVSAvoidsystem complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The proxy service acts as an intermediary that handles masking policies automatically. When a device accesses computing resources through the proxy, the service evaluates the device's zone assignment and applies appropriate masking policies to hide sensitive information. This intermediary approach improves data privacy through comprehensive masking while avoiding system complexity, as the masking logic is centralized in the proxy rather than distributed across multiple components.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20250317405A1System and Method for Controlling Access to Project Data and To Computing Resources Therefor
Publication Date: 2025.10.09 THE TORONTO DOMINION BANK
  • US20250317405A1 patent drawing
  • US20250317405A1 patent drawing
  • US20250317405A1 patent drawing

AI summary

A server device, system, method, and for controlling access to project resources is disclosed. The disclosure includes a processor, and a communications module and a memory coupled to the processor. The memory, when executed by the processor, causes the processor to generate a plurality of zones for a project, each zone defining a set of access rights to: i) a database; and ii) at least one tool. The processor configures each set of access rights to allow a proxy service to access the zones, and receives, from a client device and via the proxy service, an access query to access at least one zone. The processor provides the client device access to, via the proxy service, the at least one dataset and at least one tool of the at least one zone.