Automated Row-Level Security via Delegated Business Groups
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current access control methods in computer systems, such as those used in BI systems, often fail to provide sufficient granularity, particularly at the row level, leading to difficulties in enforcing security policies that require restricting access to specific data values or ranges within business entities, which can result in cumbersome and error-prone administration.
Innovation Solution
Implementing automated and delegated model-based row-level security by creating business groups to secure business entities within a BI data model, where users are assigned to these groups, and access is filtered based on the associated business entity values, enabling granular control over data access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If traditional role-based access control is used, then access control is simplified and easier to implement, but the granularity of security control is insufficient and cannot restrict access at row level
Solution Approach 1:
The patent segments access control into multiple levels: role-based access control for high-level security, business groups for departmental control, and row-level security for granular data access control. This segmentation allows the system to maintain ease of implementation through role-based mechanisms while achieving fine-grained control at the row level through additional filtering mechanisms.
Solution Approach 2:
The patent implements a nested security architecture where row-level security filters are nested within business group permissions, which are in turn nested within role-based access control. This nested structure allows the system to maintain the simplicity of role-based access while adding granular control capabilities through nested filtering layers.
2Measurement precision
If row-level security is implemented manually, then granular access control is achieved, but administrative complexity increases and errors occur
Solution Approach 1:
The patent implements self-service through automated security filter generation. When a business group is created or modified, the system automatically generates and applies row-level security filters based on the business entity and value assignments, eliminating the need for manual filter creation and reducing administrative complexity while maintaining granular control.
Solution Approach 2:
The patent applies preliminary action by pre-defining business groups with associated business entities and values before actual data access occurs. The security filters are pre-configured based on business group assignments, so that when users access data, the appropriate filters are already in place, reducing the need for real-time manual security configuration.
3Reliability
If access control is extended to row level, then data security is improved, but the system complexity increases
Solution Approach 1:
The patent implements universality by using a unified business group framework that handles multiple security functions: role-based access control, business group-level filtering, and row-level security filters. This multi-functional approach consolidates what would otherwise be separate complex systems into a single integrated framework, improving data security while managing system complexity through functional consolidation.
Data Source
AI summary
Business groups are created to secure business entities of a BI data model. In one aspect, a user to be secured is selected and a business group of the BI model is retrieved. Based on the business group, access to a business entity of the BI model is secured. The business group is associated with the business entity it secures. A value of the secured business entity is selected. A user is secured by assigning the user to the business group for the selected value. The value of the secured business entity is assigned to the user. In one aspect, requests from the user to access the secured business entity are filtered based on the assigned, to the user, value of the business entity.


