Analytical Access Control Translation via Source Extraction

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Managing access control information across multiple computer systems is complex, especially when data is distributed, as it requires maintaining consistency and proper formatting across systems, which can be burdensome and impractical for large volumes of data and numerous users.

Innovation Solution

The system translates transactional access control information from a transactional data source into analytical access control information for use by an analytical application program, allowing only authorized users to access specific data objects by matching user and data object identifiers, and propagates changes to ensure accurate access permissions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If access control information is specified on each of multiple computer systems to maintain consistency, then access control accuracy is improved, but device complexity and administrative burden increase

Engineering Contradiction:
Improveaccess control accuracyVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges access control information management into a single centralized location (the data source system) rather than distributing it across multiple systems. The data source system generates and maintains access control information, which is then extracted and used by other systems without requiring them to independently manage or format the same access control data, thereby reducing overall system complexity while maintaining access control accuracy.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The data source system serves multiple functions: it acts as both the operational system generating access control information and the analytical system consuming it. By making the data source system universal and multi-functional, the patent eliminates the need for separate access control management infrastructure, reducing device complexity while ensuring consistent access control across different systems.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Manufacturing precision

If access control information is manually created and updated for each system, then access control precision is improved, but loss of time and productivity decrease

Engineering Contradiction:
Improveaccess control precisionVSAvoidadministrative time
Core Design Contradiction:
Manufacturing precisionVSLoss of time

Solution Approach 1:

The patent implements preliminary action by having the data source system automatically generate and maintain access control information in advance. When data changes occur at the source, the access control information is automatically updated and propagated to other systems without requiring manual intervention, thereby maintaining high precision while eliminating time-consuming administrative tasks.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements self-service through automatic extraction and propagation of access control information. The data source system automatically updates its own access control information and propagates these updates to other systems without requiring manual creation or updating by administrators, maintaining precision while dramatically reducing the time and effort required for access control management.

Inventive Principle:
Principle #25Self-service

3Adaptability or versatility

If access control information is extracted and translated from transactional to analytical format, then adaptability is improved, but device complexity increases

Engineering Contradiction:
Improvedata format adaptabilityVSAvoidtranslation process complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary mechanism where the data source system automatically extracts and translates access control information from its native transactional format into the analytical system's required format. This intermediary translation process is automated and integrated into the data extraction workflow, providing format adaptability while minimizing the perceived complexity by handling the translation transparently within the existing data integration infrastructure.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS7421740B2Managing user authorizations for analytical reporting based on operational authorizations
Publication Date: 2008.09.02 SAP SE
  • US7421740B2 patent drawing
  • US7421740B2 patent drawing
  • US7421740B2 patent drawing

AI summary

Transactional access control information extracted from a transactional data source and used by a transactional application program is received at an analytical application program used for analytical processing. Each entry in the transactional access control information identifies a user that is permitted to access a data object that is stored in the transactional data source. The received transactional access control information is translated into analytical access control information for use by the analytical application program. Entries in the analytical access control information identify users that are able to access data objects that are stored in an analytical data store used by the analytical application program and correspond to data objects stored in the transactional data source.