Access Control Policy Generation from Choreography

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for implementing access control in collaborative business processes, especially in virtual organizations, are inadequate as they rely on manual configuration by system administrators, leading to error-prone and complex processes that are not scalable with the growing complexity of collaborations.

Innovation Solution

A method is introduced to generate and enable access control policies directly from choreography, using a dedicated access controller that implicitly represents control-flow states, decoupling access control decisions from control-flow decisions and allowing for active access control policies that align with the control flow of the collaboration, thereby reducing the need for manual configuration and enhancing scalability.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual configuration of access control policies by system administrators is used, then access control can be implemented in workflow engines, but the process becomes error-prone and not scalable with growing collaboration complexity

Engineering Contradiction:
Improveaccess control policy accuracyVSAvoidcollaboration configuration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system enables self-service by automatically generating access control policies from choreography descriptions. The policy generation component derives policies autonomously from the collaboration model without requiring manual administrator intervention, making the system adaptable to growing complexity while maintaining accuracy.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

Access control policies are generated in advance during choreography definition. The policies are prepared beforehand based on the collaboration model before actual collaboration execution begins, eliminating the need for manual configuration during runtime and reducing errors.

Inventive Principle:
Principle #10Preliminary action

2Ease of operation

If control-flow information is excluded from access control policies, then policies remain simple triplets, but access control becomes insufficiently central to workflow engine functionality

Engineering Contradiction:
Improvepolicy configuration simplicityVSAvoidworkflow engine automation
Core Design Contradiction:
Ease of operationVSExtent of automation

Solution Approach 1:

The invention merges control-flow information with access control policies by integrating the choreography description (which defines control-flow) into the policy generation process. This combination allows the workflow engine to automatically generate centralized access control policies that incorporate both access requirements and control-flow context.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If system administrators manually configure access control policies, then policies can be implemented, but time constraints and technical complexity increase error potential

Engineering Contradiction:
Improvepolicy implementation accuracyVSAvoidpolicy configuration time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The policy generation component performs self-service by automatically creating access control policies from the choreography description. This eliminates the time-consuming manual configuration process while reducing errors through automated, consistent policy generation based on the collaboration model.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The manual mechanical process of administrator configuration is replaced with an automated system that algorithmically generates policies from choreography descriptions. This substitution eliminates human error and time constraints associated with manual policy creation.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

4Device complexity

If primitive access control triplets are used, then policies are simple to define, but they cannot adequately handle sophisticated collaborative business processes

Engineering Contradiction:
Improvepolicy structure simplicityVSAvoidcollaboration process adaptability
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The generated access control policies serve multiple functions: they enforce access control, incorporate control-flow context from choreography, and adapt to sophisticated collaboration scenarios. The universal policy generation mechanism handles both simple and complex collaborative processes using a unified approach.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The policy system becomes dynamic by automatically adapting to different collaboration scenarios through choreography-driven generation. Policies are not static but are dynamically created and updated based on the specific collaboration model and control-flow requirements, enabling versatility across different business processes.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS7836483B2Automatic derivation of access control policies from a choreography
Publication Date: 2010.11.16 SAP SE
  • US7836483B2 patent drawing
  • US7836483B2 patent drawing
  • US7836483B2 patent drawing

AI summary

A system architecture and algorithm for automatically generating, installing and enforcing access control policies that correspond to an agreed specification of collaboration. A collaboration member enforces its access control policies using a dedicated access controller separate from a workflow engine. In one embodiment, each access control policy contains extensions which can direct an access controller to selectively enable or disable various access control policies upon authorization of an access request.