Methods and systems for purpose-based access control

Inventors

Otte, Arnoud

Assignees

Cambia Health Solutions Inc

Interested in licensing this patent?

MTEC can help explore whether this patent might be available for licensing for your application.

Publication Number

US-12292987-B2

Patent

Publication Date

2025-05-06

Expiration Date


Abstract

Systems and methods for purpose-based access control are provided. In one embodiment, a method for determining access to an asset comprises receiving, from a user, an access request for the asset, the access request specifying a purpose for accessing the asset, and authorizing access to the asset if the purpose is approvingly linked to the asset. In this way, unrestricted collaboration across an organization may be allowed without risking inappropriate disclosure.

Core Innovation

The invention determines access to an asset by receiving an access request that specifies a purpose for accessing the asset. At an access control engine, access is authorized when the purpose is approvingly linked to the asset, and responsive to receiving the access request, the engine traces paths through a plurality of constraints assigned to the user and to the asset.

A legal instrument is configured as a policy class that includes the plurality of constraints which limit access to resources that include the asset. The plurality of constraints include a financial attribute constraint, a self constraint, a medical attribute constraint, and a minors constraint. The engine includes a policy information point (PIP) that stores data structures defining the policy class and the relationships between the policy class and the plurality of constraints.

Access authorization further depends on re-identification thresholds for the user and for the purpose, where the re-identification thresholds correspond to re-identification scores that are not acceptable and the re-identification score is calculated based on how likely it is that a subject can be re-identified from the asset. The purpose is assigned to a Health Insurance Portability and Accountability Act (HIPAA) containment policy class, and a HIPAA object attribute is assigned to the HIPAA containment policy class and represents a containment instrument that restricts access to HIPAA data.

Responsive to receiving the access request, the engine traces paths through the plurality of constraints based on the HIPAA containment policy class and, when the asset has a path to the HIPAA object attribute, prohibits the user from requesting selected rights on assets that are not part of the HIPAA object attribute. The selected rights include a create right, an update right, and a delete right.

Claims Coverage

The partial content includes two independent claims: clm-00001 (method) and clm-00009 (system). The claims share seven core inventive features, expressed in method and system forms, including purpose-based authorization, constraint path tracing via a legal-instrument policy class, HIPAA containment constraints, and re-identification threshold-based authorization with prohibition of selected rights.

Purpose approvingly linked to asset for access authorization

Receiving an access request specifying a purpose for accessing the asset and authorizing access to the asset if the purpose is approvingly linked to the asset.

Legal instrument configured as policy class with constraints

Configuring a legal instrument as a policy class that includes a plurality of constraints limiting access to resources including the asset.

Constraint path tracing assigned to user and asset

Responsive to receiving the access request, tracing paths through a plurality of constraints that are assigned to the user and to the asset.

Policy information point storing policy class structures

Including a policy information point (PIP) that stores data structures defining the policy class and the relationships between the policy class and the plurality of constraints.

Re-identification-threshold authorization based on re-identification scores

Authorizing access if the user has a re-identification threshold that is equal to or greater than a re-identification threshold for the purpose, where the thresholds correspond to re-identification scores that are not acceptable and the re-identification score is calculated based on how likely it is that a subject can be re-identified from the asset.

HIPAA containment policy class assignment and constraint tracing

Assigning the purpose to a HIPAA containment policy class including the plurality of constraints that limit access to resources including the asset, and responsive to receiving the access request, tracing paths through the plurality of constraints assigned to the user and to the asset based on the HIPAA containment policy class.

HIPAA object attribute as containment instrument with selected rights prohibition

Assigning a HIPAA object attribute to the HIPAA containment policy class as a containment instrument, restricting access to HIPAA data, and responsive to the asset having a path to the HIPAA object attribute, prohibiting the user from requesting selected rights on assets not part of the HIPAA object attribute, where the selected rights include a create right, an update right, and a delete right.

Across clm-00001 and clm-00009, access authorization is based on purpose approvingly linked to the asset, evaluated by tracing constraint paths under a legal-instrument policy class with HIPAA containment specialization, with additional authorization gating based on re-identification thresholds and enforcement via prohibition of selected rights when the asset has no path to the HIPAA object attribute.

Stated Advantages

Not explicitly described in patent.

Documented Applications

Not explicitly described in patent.

JOIN OUR MAILING LIST

Stay Connected with MTEC

Keep up with active and upcoming solicitations, MTEC news and other valuable information.