Joint access control in multi-tenant cloud-based networks

By defining and updating data access rules in a multi-tenant cloud-based business network and combining them into the extended components, the problem that discrete components cannot directly access the core database is solved, and the consistency and security of data access control are achieved.

CN120200772APending Publication Date: 2025-06-24SAP SE
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202411505970.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2023-12-21
Filing Date
2024-10-28
Publication Date
2025-06-24

AI Technical Summary

Technical Problem

In a multi-tenant cloud-based business network, separate extension components may not be able to directly access the database of the core solution, resulting in difficulty in enforcing complex data access rules and affecting the consistency of data access control.

Method used

Enforcement of the rules is ensured by defining and updating data access rules based on the organization's association with objects and the user's association with objects, and sending these rules to the shared access control layer through the notification interface, further fusing updated rules into the extension components.

Benefits of technology

It realizes consistency and security of data access control across extended business network components, ensuring that users can only access their authorized information and prevent unauthorized access.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120200772A_ABST
    Figure CN120200772A_ABST
Patent Text Reader

Abstract

A method is provided herein, where the method includes defining a data access rule based on at least one of an association of an organization with an object and an association of a user with the object; generating a notification in response to a modification to the data access rule, where the notification includes one or more structured messages indicating the modification to the data access rule; sending the one or more structured messages to a shared access control layer via a notification interface to update the data access rules; combining the updated data access rule to one or more extension components; and enforcing the updated data access rule to control access to the object based on the updated data access rule.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The subject matter described herein generally relates to cloud services, and more specifically, to federated access control in a multi-tenant cloud-based network. Background Art

[0002] In the modern era of digital transformation, businesses are increasingly leveraging cloud-based solutions to manage their operations. One such solution is the Business Network for Asset Collaboration (BNAC), a public cloud-based multi-tenant network solution. BNAC provides an organization with a platform to collaborate and exchange asset-related information, thereby creating a single version of the truth for all involved stakeholders. Within such a network, access control is a critical aspect. Access control rules determine what information an organization or a user within an organization can access. These rules are typically based on, for example, the association of an organization with an object (or through explicit sharing) and the association of a user with an object. The complexity of these rules can increase due to cross-organizational sharing of objects and user-object access rules. Additionally, in cloud-based solutions such as BNAC, the architecture can involve discrete components. These components (which can include, for example, custom applications with business logic, reporting components, and master data governance solutions) can be used to extend the core network solution and deliver functionality to address specific business problems. These extended components can reside in separate cloud tenants or accounts and may not have access to the database of the core solution. Software as a Service (SaaS) and Platform as a Service (PaaS) models can be used in such architectures. For example, in the SaaS model, software can be hosted from a dedicated cloud tenant and consumed by one or more users over the Internet. In the PaaS model, for example, a platform can be provided to developers to build, test, and deploy applications. Both models can play a role in extending the functionality of the core network solution. Additionally, Representational State Transfer (REST)-based application programming interfaces and events can be used to facilitate communication between different system components. REST is a software architectural style that defines a set of constraints for creating web services. APIs (which are based on REST) can be used in cloud-based applications due to their scalability, statelessness, and ability to handle data in different formats. Overall, the management of access control in a multi-component extended business network for asset management in a cloud environment can involve various components and technologies, each with its own complexity and challenges. Summary of the Invention

[0003] Systems, methods, and articles of manufacture (including computer program products) are provided for federated access control in a multi-tenant cloud-based business network in a cloud environment. In one aspect, a system is provided. The system can include at least one data processor and at least one memory. The at least one memory can store instructions that, when executed by the at least one data processor, cause operations. The operations can include: defining data access rules based on at least one of an association of an organization with an object and an association of a user with an object; generating a notification in response to a modification to the data access rules, where the notification includes one or more structured messages indicating the modification to the data access rules; sending the one or more structured messages to a shared access control layer via a notification interface to update the data access rules; federating the updated data access rules to one or more extension components; and enforcing the updated data access rules to control access to the object based on the updated data access rules.

[0004] A computer-implemented method can include: defining data access rules based on at least one of an association of an organization with an object and an association of a user with an object; generating a notification in response to a modification to the data access rules, where the notification includes one or more structured messages indicating the modification to the data access rules; sending the one or more structured messages to a shared access control layer via a notification interface to update the data access rules; federating the updated data access rules to one or more extension components; and enforcing the updated data access rules to control access to the object based on the updated data access rules.

[0005] A non-transitory computer-readable medium storing instructions that, when executed by at least one data processor, cause operations including: defining data access rules based on at least one of an association of an organization with an object and an association of a user with the object; generating a notification in response to a modification to the data access rules, where the notification includes one or more structured messages indicating the modification to the data access rules; sending the one or more structured messages to a shared access control layer via a notification interface to update the data access rules; federating the updated data access rules to one or more extension components; and enforcing the updated data access rules to control access to the object based on the updated data access rules.

[0006] In some variations of the method, system, and non - transitory computer - readable medium, one or more of the following features may optionally be included in any feasible combination. In some variations, one or more extension components include custom applications with logic that has the functionality of an extended core system. In some variations, one or more extension components include a reporting component that generates reports based on data governed by data access rules in the core system. In some variations, one or more extension components include a master data governance solution integrated with the core system. In some variations, the notification interface includes an event interface that triggers the transmission of one or more structured messages to a shared access control layer in response to a modification of data access rules. In some variations, the shared access control layer updates the data access rules in real - time or near real - time to ensure compliance with updated data access rules across extension components. In some variations, the operation also includes generating one or more access control lists, where one or more access control lists respond to one or more structured messages and reflect the updated data access rules for objects.

[0007] Embodiments of the present subject matter may include methods consistent with the description provided herein and articles including tangible, embodied machine - readable media that are operable to cause one or more machines (e.g., computers, etc.) to cause operations that implement one or more of the described features. Similarly, a computer system is also described, which may include one or more processors and one or more memories coupled to the one or more processors. The memory, which may include a non - transitory computer - readable or machine - readable storage medium, may include, encode, store, etc., one or more programs that cause one or more processors to perform one or more of the operations described herein. A computer - implemented method consistent with one or more embodiments of the present subject matter may be implemented by one or more data processors residing in a single computing system or multiple computing systems. Such multiple computing systems may be connected and may exchange data and / or commands or other instructions, etc., via one or more connections (including connections via a network (e.g., the Internet, wireless wide - area network, local area network, wide - area network, wired network, etc.), via direct connections between one or more of the multiple computing systems, etc.).

[0008] Details of one or more variations of the subject matter described herein are set forth in the accompanying drawings and the description below. Other features and advantages of the subject matter described herein will be apparent from the description and drawings and from the claims. While certain features of the presently disclosed subject matter are described for illustrative purposes, it should be readily understood that these features are not intended to be limiting. The claims following this disclosure are intended to define the scope of the protected subject matter. BRIEF DESCRIPTION OF THE DRAWINGS

[0009] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate certain aspects of the subject matter disclosed herein and, together with the specification, help to explain some of the principles associated with the disclosed embodiments. In the drawings,

[0010] Figure 1 a block diagram depicts an example of a system for federated access control in accordance with some example embodiments;

[0011] Figure 2 a block diagram depicts another example of a system for federated access control in accordance with some example embodiments;

[0012] Figure 3 a flowchart depicts an example of a process for federated access control in accordance with some example embodiments; and

[0013] Figure 4 a block diagram depicts a computing system in accordance with some example embodiments.

[0014] When practical, like reference numerals denote like structures, features, or elements. DETAILED DESCRIPTION

[0015] As noted above, a network for collaboration (such as BNAC) can operate as a public cloud-based multi-tenant network solution that facilitates collaboration and information exchange regarding assets. When additional solutions are built on top of this cloud infrastructure, the additional solutions can include discrete components that may reside in separate cloud tenants. Challenges arise because these components may not have direct access to the databases of the core solution. This inability hinders the enforcement of complex data access rules that rely on organizational associations and user-object associations. Thus, this separation can create one or more problems for maintaining consistent data access control across the various components of the system. The term "solution" refers to an application or other software functionality.

[0016] In some embodiments, joint data access control in a multi-component extension system for asset management, for example, is provided. The method can involve defining and / or aggregating data access rules in a first system, such as a core system. The core system can be hosted on a dedicated cloud tenant, which can be a separate computing environment within a cloud infrastructure. In some embodiments, the dedicated cloud tenant can operate under a cloud infrastructure service model. In a cloud infrastructure service model, a single tenant, which can be an organization or a group within an organization, can have its own independent dedicated instance of the cloud infrastructure. This arrangement can indicate that the tenant does not share core computing resources, such as memory, storage, or processing power, with other tenants. The data access rules are at least partially based on the association of an organization with an object and the association of a user with that object. The object can be a record, data entity, or data element stored in a database instance. For example, data objects can be managed within a network (e.g., a system) for managing assets (e.g., data objects such as assets, documents, transaction objects, business objects, or any other type of data entity).

[0017] Figure 1 FIG. shows a block diagram of a system 100 for joint access control in a multi-tenant system that can be hosted in a cloud platform. As Figure 1 shown, the system 100 can include a host platform 110 and a client platform 120. The host platform 110 can be responsible for defining, managing, and enforcing data access rules across various client platforms in a multi-tenant environment. In some embodiments, the host platform 110 can host the core system. For example, the host platform 110 can provide the computing resources, services, and networking capabilities required for the core system and its associated components to operate. In some embodiments, the core system can be part of a cloud-based environment, such as SAP HANA Cloud, Amazon Web Services (AWS), Microsoft Azure, Google Cloud Platform (GCP), IBM Cloud, etc. In some embodiments, the host platform 110 can include the SAP HANA cloud infrastructure, AWS infrastructure, Azure infrastructure, GCP infrastructure, IBM cloud infrastructure, or the infrastructure of any other cloud service provider. Each platform can provide a set of services and resources that can support the deployment and operation of the core system.

[0018] The customer platform 120 may include a services and integration layer 122, a datasphere layer 124, custom applications 128, a reporting component 129, and a master data governance solution 126. In some embodiments, the services and integration layer 122 may act as a central hub for communication and data exchange between various components of the customer platform 120 and / or the host platform 110. In some embodiments, the services and integration layer 122 may also provide monitoring and logging capabilities to track the performance of services. The datasphere layer 124 may be responsible for data storage, management, and analysis. In some embodiments, the services and integration layer 122 may interact with the datasphere layer 124 to manage data flows, enforce access policies, and / or ensure integration across various system services. The custom applications 128 may be modules or applications tailored to specific processes or requirements, and they may perform extended functions that enhance the core capabilities of the customer platform 120. The custom applications 128 may use data access rules in the shared access control layer to control access to objects by organizations and users. This may ensure that the custom applications provide users with the information they are authorized to receive while preventing unauthorized access to sensitive data. Another extended component within the customer platform 120 is the reporting component 129, which is based on data in the core system. In some embodiments, the reporting component 129 may be supported by the services and integration layer 122. The reporting component 129 may be configured to generate reports or analytics based on data in the business network. Yet another extended component within the customer platform 120 is the master data governance solution 126, which is integrated with the core system. The master data governance solution is configured to manage master data, such as data about organizations, users, objects, and their relationships. The master data governance solution may use data access rules in the shared access control layer to control access to master data. This may ensure that the master data governance solution provides users with the master data they are authorized to receive while preventing unauthorized access to sensitive master data. The datasphere layer 124 may manage data entities within a system (e.g., the business network) to ensure consistent application of data access rules across different components of the extended network.

[0019] Figure 2 FIG. depicts a block diagram of a system 200 for federated access control in a multi-tenant cloud-based business network according to some example embodiments. As Figure 2 shown, the system 200 may include a host platform 110 and a customer platform 120. As Figure 1As shown, the host platform 110 may be responsible for defining, managing, and enforcing data access rules across various client platforms in a multi-tenant environment. In some embodiments, the client platform 120 may also include an extended application 123, a federator 125, and / or a shared access control layer 127. In some embodiments, the extended component within the client platform 120 is the extended application 123, which is a logical extension with the functions of an extended core system. The extended application 123 may be configured to perform specific functions or processes not covered by the core system. In other words, the extended application 123 represents customized or additional functions at the client platform 120 that are not provided by the core system. The extended application 123 may utilize the data access rules in the shared access control layer 127 to control access to objects by organizations and users. This can ensure that the extended application 123 provides users with the information they are entitled to while preventing unauthorized access to sensitive data.

[0020] Another component within the client platform 120 may be the federator 125, which may be configured to generate reports or analytics based on data in the network. In some embodiments, the federator 125 may act as an intermediary for merging and distributing data and policies across different components and services within the client platform 120, ensuring that data access rules and updates are applied and managed consistently throughout the system. Here, the term "federation" in context refers to the process of linking and synchronizing separate databases, applications, or systems to allow them to act as a cohesive unit, sharing and managing data and policies across different components while maintaining a level of autonomy. In some embodiments, the federator 125 may ensure that the data access rules in the shared access control layer 127 are up-to-date for each object of a user and / or organization. Such real-time or near-real-time updates can ensure that reports reflect the information that users are entitled to while preventing unauthorized access to sensitive data.

[0021] The shared access control layer 127 may be updated with the data access rules for the user's objects. In some embodiments, the shared access control layer 127 is a data structure or system component that stores and manages the data access rules for multiple components of an extended network. In some embodiments, the shared access control layer 127 may include various types of network information, such as the identities of organizations and users, the relationships between organizations and users, the types and attributes of objects, and other relevant information. This network information may include details such as user roles, permissions, organizational hierarchies, and object classifications, and thus facilitate the effective application of data access rules, ensuring that users can interact with the resources of the network in a manner that is both secure and aligned with their roles and the policies of their organizations.

[0022] The data access rules can be federated to the shared access control layer 127 via a notification interface (e.g., an event-based messaging interface, such as a publish and subscribe type event messaging framework, or a synchronization messaging interface, such as a REST-based API interface). The term "federation" refers to the process of integrating or synchronizing data access rules from a first system, such as a core solution or core system, to the shared access control layer 127 and / or then further distributing these rules to various extended components or systems. In some embodiments, the term "federation" can refer to the process of enforcing a set of centralized access control policies across different systems, components, or cloud tenants.

[0023] In some embodiments, federation (e.g., a federation process) may be triggered by one or more events. In some embodiments, the one or more events may be occurrences or changes in a system (e.g., a collaborative system or network referred to herein also as a business network) that trigger federation of data access rules, such as creation, modification, or deletion of an object, a change in the association of an organization or user with an object, or other relevant events.

[0024] In some embodiments, the data access rules also include data sensitivity rules added to the shared access control layer 127. Data sensitivity rules are a subset of data access rules that control access to data based on the sensitivity level of the data. These rules are configured to protect sensitive data by limiting access based on various factors, such as the type of data, the content of the data, the source of the data, the destination of the data, the context of data use, and other relevant factors. For example, data about financial transactions, personal information, or proprietary business information may be classified as high sensitivity data, while data about public news, general market trends, or non-confidential business operations may be classified as low sensitivity data. High sensitivity data may be limited to a limited number of users with high levels of permissions, while low sensitivity data may be accessible to a larger number of users with lower levels of permissions.

[0025] The shared access control layer 127 can communicate with extension components residing in separate cloud tenants to comply with data access rules defined by the core system. An extension component can be any component that extends the functionality of the core system, such as a custom application (e.g., Figure 1 128), reporting components (e.g. Figure 1 129), master data governance solutions (e.g. Figure 1 The extended components can utilize data access rules in the shared access control layer 127 to control access to objects by organizations and users, thereby ensuring consistent and secure data access across the extended business network. In some cases, data access rules can be configured to reflect changes in organizational roles, user permissions, and object classifications.

[0026] In some embodiments, when modifying data access rules, the system can be configured to generate a notification including one or more structured messages indicating the modification. In some embodiments, the structured message can include a formatted data packet that contains specific information about the changes made to the data access rules. For example, the structured message can include details such as the identity of the rule that was changed, the nature of the modification (e.g., addition, deletion, or update of permissions), a timestamp of when the change occurred, the user or process that initiated the change, and any relevant context that may be useful for an extended component to understand the modification. These messages are machine-readable so that they can be automatically processed by the receiving system. These structured messages are then sent via a notification interface to the shared access control layer 127 to update the data access rules. This transmission can also trigger a federation process where the updated data access rules are propagated to one or more extended components. This can ensure that all parts of the extended network operate with the latest access control information, thereby maintaining data security and integrity across different systems and components. For example, if an organization's role changes, such as from a vendor to a customer, the organization's data access rules can be updated accordingly. Similarly, if a user's permissions change, such as from read-only access to read-write access, the user's data access rules can be updated accordingly. Additionally, if an object's classification changes, such as from a public object to a private object, the object's data access rules can be updated accordingly. These updates are performed in real-time or near real-time, ensuring that data access control in the extended business network is consistently accurate and up-to-date.

[0027] Figure 3 A flowchart of a process 300 for federated access control in a multi-tenant cloud-based business network in a cloud service is depicted, which is consistent with embodiments of the present subject matter.

[0028] Process 300 can begin at operation 302, where the system can define data access rules based on at least one of an association between an organization and an object and an association between a user and the object. In some embodiments, the data access rules are defined and / or aggregated in a core system within the host platform 110 (discussed in conjunction with Figure 1 ). In some embodiments, the data access rules can be based at least in part on the association between an organization and an object and the association between a user and the same object. For example, the data access rules can define that members of the finance department can access financial reports, but within that group, only managers have the permission to edit or delete these reports. Meanwhile, employees outside of the finance department may not have access to these reports, or they may have only view access, depending on their specific role or the project they are involved in.

[0029] Next, process 300 can proceed to operation 304, where the system can generate a notification in response to a modification to the data access rules. In some embodiments, the notification can include one or more structured messages indicating the modification to the data access rules. In some embodiments, the structured message can contain information such as details of the rule change, the identity of the rule, the entities affected by the change, and the effective date and time of the rule modification. For example, the structured message can be read as "Access rule updated: The 'Confidential Project Documents' access rule (ID: AccessRule456) has been modified. The 'Project Lead' role now has 'Edit' permissions. This change affects the 'Project X Financial Forecast' document. The new access permissions will take effect at 9:00 AM UTC on April 15, 2023". In some embodiments, the structured message can be machine-readable, allowing automated systems to parse and act on the information contained therein. In some embodiments, the system can generate one or more access control lists, where the one or more access control lists respond to the one or more structured messages and reflect the updated data access rules for the object. For example, the access control list can include entries specifying which users or roles are granted or denied access to the object, the type of access permitted (e.g., read, write, edit, delete), and any conditions or constraints associated with the access (e.g., time-based restrictions, location-based restrictions).

[0030] Next, process 300 can proceed to operation 306, where the system can send one or more structured messages to the shared access control layer via a notification interface to update the data access rules. In some embodiments, the notification interface can be a communication channel that allows the system to send updates about the data access rules to the shared access control layer 127, which is responsible for enforcing access policies across various components of the system. In some embodiments, the notification interface can utilize standard messaging protocols and formats to ensure compatibility and interoperability with the shared access control layer 127. The protocol can include using RESTful APIs, message queue services, or event-driven architectures that support real-time or near-real-time updates to access control rules. In some embodiments, the notification interface can include an event interface that triggers the transmission of one or more structured messages to the shared access control layer in response to a modification to the data access rules. In some embodiments, the event interface can notify relevant components within the system of the rule change. In some embodiments, the event interface can operate under various protocols, such as HTTP / HTTPS, WebSocket, AMQP, MQTT, RESTful API, gRPC, and WebHook, to ensure compatible communication across different system components.

[0031] Next, process 300 can proceed to operation 308, where the system can federate the updated data access rules to one or more extension components. In some embodiments, the extension components can reside in a cloud tenant separate from the cloud tenant hosting the core system. In some examples, the extension components can include various services or applications that need access to the objects governed by the data access rules. In some embodiments, federating the updated data access rules involves propagating the changes to all relevant components that rely on the rule for access control decisions. This operation can ensure that the updated data access rules are enforced consistently across the system, thereby maintaining security and compliance with organizational policies.

[0032] Next, process 300 can proceed to operation 310, where the system can enforce the updated data access rules to control access to objects based on the updated data access rules. In some examples, the enforcement mechanism can include a real-time check against the updated access rules whenever an access request is made. Process 300 can ensure that extension components residing in separate cloud tenants can comply with the data access rules defined by the core system. This can provide the benefit that data access control is enforced consistently across all components of the extended business network, regardless of where they reside in the cloud infrastructure. This approach provides a controlled access environment for business users, ensuring that they can access the information they are authorized to access while preventing unauthorized access to sensitive data.

[0033] Example 1: A method includes: defining a data access rule based on at least one of an association between an organization and an object and an association between a user and the object, the data access rule being based on at least one of the association between the organization and the object and the association between the user and the object; generating a notification in response to a modification to the data access rule, where the notification includes one or more structured messages indicating the modification to the data access rule; sending the one or more structured messages to a shared access control layer via a notification interface to update the data access rule; federating the updated data access rule to one or more extension components; and enforcing the updated data access rule to control access to an object based on the updated data access rule.

[0034] Example 2: The method according to Example 1, wherein the one or more extension components include a custom application having logic that extends the functionality of the core system.

[0035] Example 3: The method according to any one of Examples 1-2, wherein the one or more extension components include a reporting component that generates reports based on data governed by the data access rule in the core system.

[0036] Example 4: The method according to any one of Examples 1-3, wherein the one or more extended components include a master data governance solution integrated with the core system.

[0037] Example 5: The method according to any one of Examples 1-4, wherein the notification interface includes an event interface that triggers the transmission of the one or more structured messages to the shared access control layer in response to a modification of the data access rules.

[0038] Example 6: The method according to any one of Examples 1-5, wherein the shared access control layer updates the data access rules in real time or near real time to ensure compliance with the updated data access rules across the extended components.

[0039] Example 7: The method according to any one of Examples 1-6, further comprising: generating one or more access control lists, wherein the one or more access control lists respond to the one or more structured messages and reflect the updated data access rules for the object.

[0040] Example 8: A system, comprising: at least one data processor, at least one memory, the at least one memory configured to store instructions that, when executed by the at least one data processor, cause operations that result in operations including: defining data access rules based on at least one of an association between an organization and an object and an association between a user and the object, the data access rules being based on at least one of an association between an organization and an object and an association between a user and the object; generating a notification in response to a modification of the data access rules, wherein the notification includes one or more structured messages indicating the modification of the data access rules; sending the one or more structured messages to a shared access control layer via a notification interface to update the data access rules; federating the updated data access rules to one or more extended components; and enforcing the updated data access rules to control access to the object based on the updated data access rules.

[0041] Example 9: The system according to Example 8, wherein the one or more extended components include a custom application having logic that extends the functionality of the core system.

[0042] Example 10: The system according to any one of Examples 8-9, wherein the one or more extended components include a reporting component that generates reports based on data governed by the data access rules in the core system.

[0043] Example 11: The system according to any one of Examples 8-10, wherein the one or more extended components include a master data governance solution integrated with the core system.

[0044] Example 12: The system according to any one of Examples 8-11, wherein the notification interface includes an event interface that triggers transmission of the one or more structured messages to the shared access control layer in response to a modification to the data access rule.

[0045] Example 13: The system according to any one of Examples 8-12, wherein the shared access control layer updates the data access rule in real time or near real time to ensure compliance with the updated data access rule across the extended components.

[0046] Example 14: The system according to any one of Examples 8-13, wherein the operation further includes: generating one or more access control lists, wherein the one or more access control lists respond to the one or more structured messages and reflect updated data access rules for the object.

[0047] Example 15: A non-transitory computer-readable medium storing instructions that, when executed by at least one data processor, cause operations including: defining a data access rule based on at least one of an association of an organization with an object and an association of a user with the object, the data access rule being based on at least one of an association of an organization with an object and an association of a user with the object; generating a notification in response to a modification to the data access rule, wherein the notification includes one or more structured messages indicating the modification to the data access rule; sending the one or more structured messages to a shared access control layer via a notification interface to update the data access rule; federating the updated data access rule to one or more extended components; and enforcing the updated data access rule to control access to the object based on the updated data access rule.

[0048] Example 16: The non-transitory computer-readable medium according to Example 15, wherein the one or more extended components include a custom application having logic with functionality of an extended core system.

[0049] Example 17: The non-transitory computer-readable medium according to any one of Examples 15-16, wherein the one or more extended components include a reporting component that generates a report based on data governed by the data access rule in the core system.

[0050] Example 18: The non-transitory computer-readable medium according to any one of Examples 15-17, wherein the one or more extended components include a master data governance solution integrated with the core system.

[0051] Example 19: The non-transitory computer-readable medium according to any one of Examples 15-18, wherein the notification interface includes an event interface that triggers transmission of the one or more structured messages to the shared access control layer in response to a modification to the data access rules.

[0052] Example 20: The non-transitory computer-readable medium according to any one of Examples 15-19, wherein the shared access control layer updates the data access rules in real time or near real time to ensure compliance with the updated data access rules across the extended components.

[0053] Figure 4 A block diagram depicting a computing system 400 illustrative of an implementation consistent with the current subject matter is shown. As Figure 4 shown, the computing system 400 may include a processor 410, a memory 420, a storage device 430, and an input / output device 440. The processor 410, the memory 420, the storage device 430, and the input / output device 440 may be interconnected via a system bus 450. The processor 410 is capable of processing instructions for execution within the computing system 400. Instructions so executed may implement, for example, one or more components of the host platform 110 and the client platform 120. In some implementations of the current subject matter, the processor 410 may be a single-threaded processor. Alternatively, the processor 410 may be a multi-threaded processor. The processor 410 is capable of processing instructions stored in the memory 420 and / or on the storage device 430 to display graphical information of a user interface provided via the input / output device 440.

[0054] The memory 420 is a computer-readable medium for storing information within the computing system 400, such as volatile or non-volatile. For example, the memory 420 may store data structures representing a configuration object database. The storage device 430 is capable of providing persistent storage for the computing system 400. The storage device 430 may be a solid-state device, a floppy disk device, a hard disk device, an optical disk device, a tape device, and / or any other suitable persistent storage device. The input / output device 440 provides input / output operations for the computing system 400. In some implementations of the current subject matter, the input / output device 440 includes a keyboard and / or a pointing device. In various implementations, the input / output device 440 includes a display unit for displaying a graphical user interface.

[0055] According to some implementations of the current subject matter, the input / output device 440 may provide input / output operations for a network device. For example, the input / output device 440 may include an Ethernet port or other networking port to communicate with one or more wired and / or wireless networks (e.g., a local area network (LAN), a wide area network (WAN), the Internet).

[0056] In some embodiments of the present subject matter, the computing system 400 can be used to execute various interactive computer software applications, which can be used to organize, analyze, and / or store data in various (e.g., tabular) formats (e.g., Microsoft Excel@ and / or any other type of software). Alternatively, the computing system 400 can be used to execute any type of software application. These applications can be used to perform various functions, such as, for example, planning functions (e.g., generating, managing, editing spreadsheet documents, word processing documents, and / or any other objects, etc.), computing functions, communication functions, etc. The applications can include various plug-in functions (e.g., the SAP Integrated Business Planning add-in for Microsoft Excel as part of the SAP Business Suite, as provided by SAP SE of Walldorf, Germany), or can be stand-alone computing products and / or functions. When activated within an application, the functions can be used to generate a user interface provided via the input / output device 440. The user interface can be generated by the computing system 400 and presented to the user (e.g., on a computer screen monitor, etc.).

[0057] One or more aspects or features of the subject matter described herein can be implemented in digital electronic circuitry, integrated circuitry, specially designed ASICs, field programmable gate array computer hardware, firmware, software, and / or combinations thereof. These various aspects or features can include an implementation in one or more computer programs executable and / or interpretable on a programmable system including at least one programmable processor, which can be special purpose or general purpose, coupled to receive data and instructions from, and to send data and instructions to, a storage system, at least one input device, and at least one output device. The programmable system or computing system can include clients and servers. The clients and servers are typically remote from each other and typically interact via a communication network. The relationship of the client and server arises by virtue of computer programs running on the respective computers and having a client-server relationship to each other.

[0058] These computer programs (which may also be referred to as programs, software, software applications, applications, components, or code) include machine instructions for a programmable processor and can be implemented in a high-level procedural and / or object-oriented programming language and / or in assembly / machine language. As used herein, the term "machine-readable medium" refers to any computer program product, apparatus, and / or device, such as for example a disk, optical disk, memory, and programmable logic device (PLD), that provides machine instructions and / or data to a programmable processor, including a machine-readable medium that receives machine instructions as a machine-readable signal. The term "machine-readable signal" refers to any signal that provides machine instructions and / or data to a programmable processor. A machine-readable medium may non-transitorily store such machine instructions, such as, for example, as in non-transitory solid state memory or a magnetic hard disk drive or any equivalent storage medium. A machine-readable medium may alternatively or additionally store such machine instructions in a transient manner, such as, for example, as in a processor cache or other random access memory associated with one or more physical processor cores.

[0059] To provide for interaction with a user, one or more aspects or features of the subject matter described herein may be implemented on a computer having a display device (such as, for example, a cathode ray tube (CRT), or a liquid crystal display (LCD), or a light emitting diode (LED) monitor) for displaying information to the user and a keyboard and a pointing device (such as, for example, a mouse or a trackball) by which the user can provide input to the computer. Other kinds of devices may also be used to provide for interaction with the user. For example, the feedback provided to the user may be any form of sensory feedback, such as, for example, visual feedback, auditory feedback, or tactile feedback; and the input received from the user may be in any form, including sound, voice, or tactile input. Other possible input devices include a touch screen or other touch-sensitive device, such as a single-point or multi-point resistive or capacitive trackpad, speech recognition hardware and software, optical scanners, optical pointers, digital image capture devices and associated interpretation software, and the like.

[0060] In the foregoing description and claims, phrases such as "at least one of... " or "one or more of... " may appear, followed by a list of elements or features in conjunction. The term "and / or" may also appear in a list of two or more elements or features. Unless otherwise implicitly or explicitly contradicted by the context in which it is used, such phrases are intended to mean either any one of the listed elements or features, or any combination of any one of the listed elements or features with any other of the listed elements or features. For example, the phrases "at least one of A and B;" "one or more of A and B;" and "A and / or B" each are intended to mean "A alone, B alone, or A and B together." Similar interpretations are intended for lists including three or more items. For example, the phrases "at least one of A, B, and C;" "one or more of A, B, and C;" and "A, B, and / or C" each are intended to mean "A alone, B alone, C alone, A and B together, A and C together, B and C together, or A and B and C together." The use of the term "based on" in the foregoing and in the claims is intended to mean "at least in part based on," such that unrecited features or elements are also permitted.

[0061] Depending on the desired configuration, the subject matter described herein may be embodied in a system, apparatus, method, and / or article. The embodiments set forth in the foregoing description do not represent all embodiments consistent with the subject matter described herein. Rather, they are only some examples consistent with aspects related to the described subject matter. Although some variations have been described in detail above, other modifications or additions are possible. In particular, additional features and / or variations may be provided in addition to those set forth herein. For example, the above embodiments may relate to various combinations and sub - combinations of the disclosed features and / or combinations and sub - combinations of several additional features disclosed above. Additionally, the logical flows depicted in the figures and / or described herein do not necessarily need the particular order or sequential order shown to achieve the desired result. For example, without departing from the scope of the present disclosure, the logical flow may include operations different from and / or additional to those shown. One or more operations of the logical flow may be repeated and / or omitted without departing from the scope of the present disclosure. Other embodiments may be within the scope of the appended claims.

Claims

1. A method comprising: defining a data access rule based on at least one of an association of an organization with an object and an association of a user with the object; generating a notification in response to a modification to the data access rule, wherein the notification includes one or more structured messages indicating the modification to the data access rule; sending the one or more structured messages to a shared access control layer via a notification interface to update the data access rules; federating the updated data access rules to one or more extension components; and The updated data access rules are enforced to control access to the object based on the updated data access rules.

2. The method according to claim 1, wherein: The one or more extension components include custom applications having logic that extends the functionality of the core system.

3. The method according to claim 1, wherein: The one or more extension components include a reporting component that generates reports based on data in the core system governed by the data access rules.

4. The method according to claim 1, wherein: The one or more extension components include a master data governance solution integrated with the core system.

5. The method according to claim 1, wherein: The notification interface includes an event interface that triggers transmission of the one or more structured messages to the shared access control layer in response to the modification to the data access rules.

6. The method according to claim 1, wherein: The shared access control layer updates the data access rules in real time or near real time to ensure compliance with the updated data access rules across the extended components.

7. The method according to claim 1, further comprising: One or more access control lists are generated, wherein the one or more access control lists are responsive to the one or more structured messages and reflect the updated data access rules for the object.

8. A system comprising: at least one data processor; as well as at least one memory storing instructions that, when executed by the at least one data processor, cause operations comprising: defining a data access rule based on at least one of an association of an organization with an object and an association of a user with the object; generating a notification in response to a modification to the data access rule, wherein the notification includes one or more structured messages indicating the modification to the data access rule; sending the one or more structured messages to a shared access control layer via a notification interface to update the data access rules; federating the updated data access rules to one or more extension components; and The updated data access rules are enforced to control access to the object based on the updated data access rules.

9. The system according to claim 8, wherein: The one or more extension components include custom applications having logic that extends the functionality of the core system.

10. The system according to claim 8, wherein: The one or more extension components include a reporting component that generates reports based on data in the core system governed by the data access rules.

11. The system according to claim 8, wherein: The one or more extension components include a master data governance solution integrated with the core system.

12. The system according to claim 8, wherein: The notification interface includes an event interface that triggers transmission of the one or more structured messages to the shared access control layer in response to a modification to the data access rules.

13. The system according to claim 8, wherein: The shared access control layer updates the data access rules in real time or near real time to ensure compliance with the updated data access rules across the extended components.

14. The system according to claim 8, wherein: The operations also include: One or more access control lists are generated, wherein the one or more access control lists are responsive to the one or more structured messages and reflect the updated data access rules for the object.

15. A non-transitory computer-readable medium storing instructions that, when executed by at least one data processor, cause operations comprising: defining a data access rule based on at least one of an association of an organization with an object and an association of a user with the object; generating a notification in response to a modification to the data access rule, wherein the notification includes one or more structured messages indicating the modification to the data access rule; sending the one or more structured messages to a shared access control layer via a notification interface to update the data access rules; federating the updated data access rules to one or more extension components; and The updated data access rules are enforced to control access to the object based on the updated data access rules.

16. The non-transitory computer readable medium of claim 15, wherein: The one or more extension components include custom applications having logic that extends the functionality of the core system.

17. The non-transitory computer readable medium of claim 15, wherein: The one or more extension components include a reporting component that generates reports based on data in the core system governed by the data access rules.

18. The non-transitory computer readable medium of claim 15, wherein: The one or more extension components include a master data governance solution integrated with the core system.

19. The non-transitory computer readable medium of claim 15, wherein: The notification interface includes an event interface that triggers transmission of the one or more structured messages to the shared access control layer in response to a modification to the data access rules.

20. The non-transitory computer readable medium of claim 15, wherein: The shared access control layer updates the data access rules in real time or near real time to ensure compliance with the updated data access rules across the extended components.