Centralized Authorization Policy Server for Multi-Application Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Managing authorization policies consistently across multiple application programs is challenging due to the presence of different authorization systems and user interfaces, making it difficult for IT managers to implement and maintain uniform policies.
Innovation Solution
A system and method that utilize a policy server, secured viewing server, content access governor, and data protection client to control access to protected documents, where policies are sent through APIs to determine user rights and enforce access controls, ensuring consistent authorization across applications.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If authorization policies are implemented within each application program individually, then each application can enforce its own access control rules, but managing and maintaining consistent policies across multiple applications becomes complex and difficult
Solution Approach 1:
The patent introduces an authorization provider as an intermediary component that centralizes authorization policy management. This provider receives authorization requests from multiple application programs and applies consistent policies across all applications, eliminating the need for each application to independently manage its own authorization logic while maintaining policy consistency across the entire system
Solution Approach 2:
The authorization provider serves as a universal component that handles authorization requests from diverse application programs through a common interface (HTTP-based API). This multi-functional approach allows a single authorization system to serve multiple applications with different requirements while maintaining consistent policy enforcement across all of them
2Adaptability or versatility
If multiple authorization systems are used across different applications, then each application can have customized authorization logic, but integration and policy uniformity become challenging
Solution Approach 1:
The patent segments the authorization system into two distinct parts: a centralized authorization provider that handles policy management and decision-making, and application programs that simply submit requests through standardized interfaces. This segmentation allows applications to maintain their specific authorization requirements while relying on the centralized provider for consistent policy enforcement
Solution Approach 2:
The authorization provider acts as an intermediary layer between application programs and the actual authorization policies. Applications interact with this intermediary through a standard HTTP-based API, which translates their specific authorization needs into consistent policy evaluations, thereby maintaining both customization and uniformity
3Reliability
If centralized authorization policy management is implemented, then policy consistency across applications is improved, but system integration complexity increases
Solution Approach 1:
The authorization provider implements a universal HTTP-based API that can be integrated into any application program regardless of its programming language or platform. This standardized interface simplifies integration by providing a common communication protocol, reducing the complexity that would otherwise arise from custom integration code for each application
Solution Approach 2:
The system uses template-based policy definitions that can be copied and applied across multiple applications. Once an authorization policy is created and validated in the centralized provider, it can be replicated across different applications through the standardized API, reducing integration complexity while maintaining consistency
Data Source
AI summary
A technique and system provide protection to information or documents via an authorization policy that is applied to multiple application programs and authorization requests are submitted through a REST API over HTTP or HTTPS. Methods, techniques, and systems control access to protected information or documents and use of content in protected information or documents to support information management policies.


