Automated Row-Level Security via Delegated Business Groups

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current access control methods in computer systems, such as those used in BI systems, often fail to provide sufficient granularity, particularly at the row level, leading to difficulties in enforcing security policies that require restricting access to specific data values or ranges within business entities, which can result in cumbersome and error-prone administration.

Innovation Solution

Implementing automated and delegated model-based row-level security by creating business groups to secure business entities within a BI data model, where users are assigned to these groups, and access is filtered based on the associated business entity values, enabling granular control over data access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If traditional role-based access control is used, then access control is simplified and easier to implement, but the granularity of security control is insufficient and cannot restrict access at row level

Engineering Contradiction:
Improveease of access control implementationVSAvoidgranularity of security control
Core Design Contradiction:
Ease of operationVSMeasurement precision

Solution Approach 1:

The patent segments access control into multiple levels: role-based access control for high-level security, business groups for departmental control, and row-level security for granular data access control. This segmentation allows the system to maintain ease of implementation through role-based mechanisms while achieving fine-grained control at the row level through additional filtering mechanisms.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements a nested security architecture where row-level security filters are nested within business group permissions, which are in turn nested within role-based access control. This nested structure allows the system to maintain the simplicity of role-based access while adding granular control capabilities through nested filtering layers.

Inventive Principle:
Principle #7Nested doll (Nesting)

2Measurement precision

If row-level security is implemented manually, then granular access control is achieved, but administrative complexity increases and errors occur

Engineering Contradiction:
Improvegranularity of security controlVSAvoidadministrative complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent implements self-service through automated security filter generation. When a business group is created or modified, the system automatically generates and applies row-level security filters based on the business entity and value assignments, eliminating the need for manual filter creation and reducing administrative complexity while maintaining granular control.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent applies preliminary action by pre-defining business groups with associated business entities and values before actual data access occurs. The security filters are pre-configured based on business group assignments, so that when users access data, the appropriate filters are already in place, reducing the need for real-time manual security configuration.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If access control is extended to row level, then data security is improved, but the system complexity increases

Engineering Contradiction:
Improvedata securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements universality by using a unified business group framework that handles multiple security functions: role-based access control, business group-level filtering, and row-level security filters. This multi-functional approach consolidates what would otherwise be separate complex systems into a single integrated framework, improving data security while managing system complexity through functional consolidation.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9870407B2Automated and delegated model-based row level security
Publication Date: 2018.01.16 SAP SE
  • US9870407B2 patent drawing
  • US9870407B2 patent drawing
  • US9870407B2 patent drawing

AI summary

Business groups are created to secure business entities of a BI data model. In one aspect, a user to be secured is selected and a business group of the BI model is retrieved. Based on the business group, access to a business entity of the BI model is secured. The business group is associated with the business entity it secures. A value of the secured business entity is selected. A user is secured by assigning the user to the business group for the selected value. The value of the secured business entity is assigned to the user. In one aspect, requests from the user to access the secured business entity are filtered based on the assigned, to the user, value of the business entity.