Common Authorization Management Service for Multi-Provider Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Managing administrative authorization and access rights for individuals across multiple service providers is challenging due to the complexity of tracking roles and access levels, often requiring administrators to be familiar with various administrative tools and policies.
Innovation Solution
A Common Authorization Management (CAM) service with a web interface is introduced to delegate access rights management between enterprises and service providers, allowing administrators to create groups, receive security data, and associate individuals with access rights to services across multiple service providers, thereby simplifying the process.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If administrators manually manage access rights for individuals across multiple service providers, then access control can be precisely configured, but the complexity and time required for management increases significantly
Solution Approach 1:
The patent introduces a Common Authorization Management (CAM) service as an intermediary system between enterprises and service providers. This CAM service acts as a mediator that receives authorization requests from service providers, validates them against enterprise policies, and manages the mapping between individuals and access rights. This intermediary layer simplifies the management complexity while maintaining precise access control by centralizing the authorization logic.
Solution Approach 2:
The CAM service provides a universal platform that can manage access rights across multiple different service providers simultaneously. Instead of requiring separate management systems for each service provider, the patent creates a multi-functional system that handles authorization for various services through a single unified interface, reducing the overall management burden while maintaining specificity where needed.
2Reliability
If administrators use multiple administrative tools from different service providers, then access rights can be precisely controlled, but the time and expertise required increases
Solution Approach 1:
The patent merges the authorization management functions from multiple service providers into a single unified CAM service. Instead of requiring administrators to interact with separate administrative tools for each service provider, the system combines these functions into one centralized platform where all authorization requests are processed through a common interface, significantly reducing management time while maintaining precise control.
Solution Approach 2:
The CAM service implements self-service mechanisms where service providers can automatically submit authorization requests, and the system automatically processes these requests against stored enterprise policies. This reduces the manual intervention time required from administrators while maintaining precise access rights control through automated policy enforcement.
3Reliability
If administrators track individual roles and access levels across multiple enterprises, then accurate access control is achieved, but the difficulty of tracking and managing increases
Solution Approach 1:
The patent segments the authorization management process into distinct components: individual authorization records are maintained separately from enterprise policies, and the CAM service processes these segments independently. This segmentation allows for accurate tracking of individual access rights while simplifying the overall management process by breaking down the complex tracking task into manageable, discrete operations.
Solution Approach 2:
The system implements feedback mechanisms where the CAM service receives authorization requests from service providers, processes them against stored enterprise policies, and returns authorization decisions. This feedback loop enables accurate access control by continuously validating individual roles against policy requirements while making the tracking process more manageable through automated policy-based decision-making.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
An improved method in a computing environment for establishing access for individuals in at least one enterprise with one or more services provided by a plurality of service providers through the use of a Common Authorization Management (CAM) service is described herein. Through the CAM service, an enterprise administrator can group together one or more individuals at one enterprise, identify access rights to one or more services in the plurality of service providers for each group of individuals based on security data defined by a service provider administrator, and associate individuals from the subset of the plurality of groups at each enterprise with access rights to one or more services provided by the plurality of service providers.