Centralized Access Management System for Role-Based Permission Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Managing user access to multiple company resources is complex due to varying interfaces and access mechanisms, especially for large organizations with diverse employee roles and permissions.

Innovation Solution

An access management system that receives a single access change request message, identifies the affected resources based on user roles or work groups, and transmits event messages to modify access permissions across multiple resources, allowing for granting, suspending, or revoking access, with acknowledgement messages confirming changes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a centralized access management system is implemented to simplify user access control across multiple resources, then ease of operation is improved, but device complexity increases due to the need to integrate with multiple resources having different interfaces and access mechanisms

Engineering Contradiction:
Improveease of user access managementVSAvoidsystem complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent implements a centralized access management system that acts as an intermediary between users and multiple resources. This mediator receives access requests, determines appropriate permissions based on user roles and policies, and translates them into resource-specific access controls. The intermediary handles the complexity of integrating with different resource interfaces internally, while presenting a simplified interface to users and administrators.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If separate access management procedures are used for each resource, then adaptability to different resource interfaces is improved, but loss of time increases due to manual management of multiple access control systems

Engineering Contradiction:
Improveadaptability to resource interfacesVSAvoidtime for access management
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The patent creates a universal access management system capable of handling multiple resource types through a single interface. The system employs standardized protocols and abstraction layers that enable it to work with diverse resources (applications, databases, servers, etc.) without requiring separate management procedures for each. This multi-functional approach allows the system to adapt to different resource interfaces while maintaining consistent, automated access control workflows.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Productivity

If automated access management is implemented across multiple resources, then productivity is improved through centralized control, but device complexity increases due to integration requirements with different resource systems

Engineering Contradiction:
Improveefficiency of access managementVSAvoidintegration complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent segments the access management functionality into distinct modular components, each responsible for specific tasks such as user authentication, permission determination, access request routing, and resource-specific protocol handling. This segmentation allows the system to automate access management across multiple resources while managing integration complexity through standardized interfaces between modules. Each segment can be independently configured and maintained, reducing the overall complexity burden.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11582239B2User access and identity life-cycle management
Publication Date: 2023.02.14 INTUIT INC
  • US11582239B2 patent drawing
  • US11582239B2 patent drawing
  • US11582239B2 patent drawing

AI summary

A method and processing system for managing user access to one or more resources is disclosed. A central service may receive an access change request message regarding a user. The access change request message may include a user identifier, a user role, and an access action for the user. Example access actions may include adding or removing user access with respect to a resource. The central service may determine which resources are associated with the user role and transmit one or more event messages to the resources to implement the access actions. The resources may send acknowledgement messages to the central service to confirm that the access actions have been completed.