Authorization Scope Management for Low-Code Workflows

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In low-code programming environments, non-technical users often misconfigure authorization scopes, leading to excessive privileges being granted to low-code programs, which can pose security risks.

Innovation Solution

A device receives a set of actions for a low-code workflow specified via a user interface, determines authorization scopes for the targets of these actions, compares them to the scopes needed, and provides an excessive authorization notification when the scopes exceed what is necessary.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If non-technical users are allowed to configure authorization scopes in low-code environments, then ease of operation is improved, but manufacturing precision deteriorates due to misconfiguration of authorization scopes

Engineering Contradiction:
Improveease of operationVSAvoidauthorization scope configuration precision
Core Design Contradiction:
Ease of operationVSManufacturing precision

Solution Approach 1:

The system introduces an intermediary authorization management mechanism that automatically analyzes workflow actions and determines appropriate authorization scopes. This intermediary layer prevents non-technical users from directly misconfiguring scopes while still allowing them to create workflows, thus resolving the contradiction between ease of operation and configuration precision

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system provides feedback by analyzing the workflow actions and comparing them against the configured authorization scopes. When scopes are excessive or inappropriate, the system can alert users and suggest corrections, ensuring that authorization precision is maintained while allowing non-technical users to operate the system

Inventive Principle:
Principle #23Feedback

2Device complexity

If non-technical users are empowered to create programs, then device complexity is reduced, but reliability deteriorates due to security risks from excessive privileges

Engineering Contradiction:
Improvedevice complexityVSAvoidsecurity reliability
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent introduces an intermediary authorization management system that automatically determines appropriate authorization scopes for workflow actions. This intermediary layer maintains security reliability by preventing excessive privilege assignment while allowing non-technical users to create programs without dealing with complex authorization configurations

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system provides self-service authorization management by automatically analyzing workflow actions and assigning appropriate authorization scopes without requiring manual configuration by users. This maintains reliability while keeping the system simple for non-technical users

Inventive Principle:
Principle #25Self-service

3Device complexity

If authorization management is left to programmers, then device complexity is reduced, but manufacturing precision deteriorates due to misconfiguration of authorization scopes

Engineering Contradiction:
Improvedevice complexityVSAvoidauthorization scope configuration precision
Core Design Contradiction:
Device complexityVSManufacturing precision

Solution Approach 1:

The system implements feedback mechanisms that automatically analyze workflow actions and compare them against configured authorization scopes. This feedback loop ensures that authorization scopes are precisely matched to actual needs, preventing misconfiguration while keeping the system simple for users

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent introduces an intermediary authorization management layer that automatically determines appropriate scopes based on workflow actions. This intermediary prevents misconfiguration by non-technical users while maintaining simple device architecture

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12294583B2Authorization scope management for low-code programming environments
Publication Date: 2025.05.06 CISCO TECHNOLOGY INC
  • US12294583B2 patent drawing
  • US12294583B2 patent drawing
  • US12294583B2 patent drawing

AI summary

In one embodiment, a device receives a set of actions for a low-code workflow specified via a user interface. The device determines authorization scopes for targets of the set of actions. The device compares the authorization scopes for the targets to authorization scopes needed for the set of actions. The device provides, to the user interface, an excessive authorization notification, when the authorization scopes for the targets exceed the authorization scopes needed for the set of actions.