Activatable Access Rules for Granular Information Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems for managing access to digital information in e-business environments lack flexibility in authorizing user actions on information instances, as they rely on role-based access management and access control lists, which do not allow for selective and granular control over access permissions.

Innovation Solution

A computer program product that enables administrators to selectively activate rules for authorizing user actions on information instances, allowing for flexible management of access permissions through a graphical user interface, where rules can be grouped by work center software modules and configured to limit general authorizations based on predefined subjects and objects, including document status.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If role-based access management systems are used to manage authorizations by assigning information instances to actors, then access control is established, but flexibility in selectively controlling access permissions is reduced

Engineering Contradiction:
Improveflexibility in access controlVSAvoidaccess management system complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The access management system is segmented into modular rules, each rule representing a discrete authorization decision. These rules can be independently activated or deactivated, allowing flexible control over access permissions without restructuring the entire system. Each rule acts as an independent segment that can be managed separately.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system introduces dynamic rule activation capabilities, where rules can be selectively turned on or off based on changing business requirements. This dynamic control mechanism allows the system to adapt access permissions in real-time without requiring complex reconfiguration of the underlying access management infrastructure.

Inventive Principle:
Principle #15Dynamics

2Ease of operation

If access control lists are used to assign particular actors to individual instances, then specific access permissions are granted, but granular control over access permissions is limited

Engineering Contradiction:
Improveaccess permission controlVSAvoidgranular authorization control
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

Each rule in the system applies local quality by specifying precise conditions for particular information instances, actors, and actions. Rules can be configured with specific criteria that apply only to certain documents or data types, enabling granular control over access permissions at the individual instance level rather than applying blanket restrictions.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system allows dynamic modification of rule parameters including activation status, applicable actors, information instances, and permitted actions. Administrators can change these parameters to achieve different levels of granularity in access control without recreating the entire access control list structure.

Inventive Principle:
Principle #35Parameter changes

3Productivity

If general authorization is provided by work center software modules, then users can perform predefined actions, but selective restriction of authorizations is difficult

Engineering Contradiction:
Improveuser action efficiencyVSAvoidauthorization restriction flexibility
Core Design Contradiction:
ProductivityVSAdaptability or versatility

Solution Approach 1:

The system implements preliminary action by providing general authorization through work center software modules for common user actions. This allows users to perform predefined actions efficiently without needing explicit permission for each individual operation, maintaining high productivity for routine tasks.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

Rules act as intermediaries between the general authorization provided by work center software modules and the specific access control requirements. These intermediary rules can selectively restrict or override general authorizations when specific conditions are met, providing flexible control without undermining the efficiency of general authorization.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS7703033B2Access administration using activatable rules
Publication Date: 2010.04.20 SAP SE
  • US7703033B2 patent drawing
  • US7703033B2 patent drawing
  • US7703033B2 patent drawing

AI summary

Access to information instances is administered using selectively activatable rules. A computer program product includes rules establishing authorizations to information instances in a computer system, each of the rules authorizing a predefined subject to perform a predefined action on a predefined object. The computer program product includes an activation function for an administrator to selectively activate at least one of the rules, the activated rule to be applied upon a user seeking to perform an action on any of the information instances.