Communities Framework Dual-Layer Security Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current collaborative computing environments are rigid and inflexible, lacking dynamic security and customization options, making it difficult to manage changing user permissions and adapt to evolving enterprise needs.

Innovation Solution

A communities framework that implements a dual-layer security system, using membership and functional capabilities to control access, combined with entitlements and security policies, allowing for hierarchical relationships and inheritance, enabling flexible and efficient user access management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If traditional security models are used in collaborative computing environments, then basic access control is provided, but the system becomes rigid and inflexible when managing changing user permissions

Engineering Contradiction:
Improveflexibility in managing user permissionsVSAvoidcomplexity of security management system
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the security model into two distinct layers: membership/functional capabilities (Level 1) and entitlements/security policies (Level 2). This segmentation allows each layer to handle specific aspects of access control independently, providing flexibility in managing user permissions without creating a monolithic complex system. The layered approach enables granular control where Level 1 handles basic access rights and Level 2 handles detailed security policies.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a dual-layer security architecture that adds a dimensional aspect to traditional flat security models. By stacking Level 1 (membership and functional capabilities) and Level 2 (entitlements and security policies), the system creates a multi-dimensional security framework that can accommodate complex permission requirements while maintaining manageability through clear separation of concerns.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Reliability

If detailed security controls are implemented for each user, then precise access control is achieved, but the complexity of managing large numbers of users increases significantly

Engineering Contradiction:
Improveprecision of access controlVSAvoidcomplexity of user management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements universal security templates and role-based access control that can be applied across multiple users simultaneously. Instead of configuring security controls individually for each user, the system allows administrators to define security policies at the group or role level, which then automatically apply to all members. This universal approach maintains precise access control while dramatically reducing the complexity of managing large numbers of users.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system performs preliminary security configuration through pre-defined membership templates, functional capability profiles, and security policy templates. These pre-configured elements can be assigned to users and groups in advance, eliminating the need for detailed individual configuration later. This preliminary action approach ensures precise access control is achieved while minimizing the ongoing complexity of user management.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If custom security policies are created for different user groups, then adaptability to enterprise needs improves, but the configuration complexity increases

Engineering Contradiction:
Improvecustomization to enterprise needsVSAvoidease of security configuration
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent implements dynamic security configuration where security policies, membership definitions, and functional capabilities can be easily modified without requiring system reconfiguration. The dual-layer architecture allows administrators to dynamically adjust Level 1 membership/functional capabilities and Level 2 entitlements/security policies based on changing enterprise needs. This dynamic approach maintains high adaptability while preserving ease of operation through a user-friendly configuration interface.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent introduces security templates and role definitions as intermediary elements that simplify the configuration process. Instead of directly configuring complex security policies for each user group, administrators work with pre-defined templates and roles that act as intermediaries. These intermediaries encapsulate complex security configurations, making them easier to create, modify, and manage while still providing comprehensive customization capabilities for enterprise needs.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8185643B2System and method for providing security in a communities framework
Publication Date: 2012.05.22 ORACLE INT CORP
  • US8185643B2 patent drawing
  • US8185643B2 patent drawing
  • US8185643B2 patent drawing

AI summary

Systems and methods are disclosed for providing security for a communities framework in a collaborative computing environment. A community can be provided for maintaining user membership during collaboration. The community can contain various collaboration resources, community services and members having access to the resources and services. A first layer of security can be implemented via membership and functional capabilities. Members can be assigned to various membership capabilities and these membership capabilities can be mapped to functional capabilities in order to control access to the resources by the various members. A second layer of security can be implemented via entitlements and security policies applied to the content repository. Entitlements can be applied at a node level of a content repository. Each node can be evaluated when operations are requested for it.