Credential Management for Secure Enterprise Search Crawling

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing search systems face challenges in securely accessing and indexing content across enterprise applications with dynamic security hierarchies, as they lack the ability to handle varying security attributes and user roles that change frequently, leading to complications in crawling and indexing processes.

Innovation Solution

A flexible and extensible architecture that enables authentication, authorization, and secure enterprise search by accepting user identification information in arbitrary formats, using identity management systems to validate users, and appending security attributes to queries for real-time access control, allowing for dynamic querying and secure access to multiple data sources.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a crawler is programmed to be aware of all security requirements of each application or source, then secure access to multiple data sources is enabled, but the crawling process becomes drastically complicated and slowed down

Engineering Contradiction:
Improvesecure accessVSAvoidcrawling process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a credential management system that acts as an intermediary between the crawler and multiple data sources. This system stores credentials for multiple applications and automatically provides appropriate credentials to the crawler during the crawling process, eliminating the need for the crawler to be programmed with knowledge of each application's security requirements while maintaining secure access.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If security credentials are stored for multiple applications, then access to multiple data sources is enabled, but the credential storage and management becomes complex

Engineering Contradiction:
Improveaccess to multiple data sourcesVSAvoidcredential management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent creates a universal credential management system that can handle multiple application credentials through a single interface. The system stores credentials for multiple different applications in a unified repository and provides them through standardized methods, allowing the crawler to access diverse data sources without requiring application-specific credential management logic.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Productivity

If the crawler accesses secure sources using stored credentials, then automated crawling is enabled, but the credentials may be used beyond their intended lifespan or purpose

Engineering Contradiction:
Improveautomated crawlingVSAvoidcredential usage control
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent implements a feedback mechanism where the credential management system tracks and monitors credential usage. The system provides methods to verify that credentials are being used within their intended lifespan and for authorized purposes, allowing the crawler to operate automatically while maintaining control over credential validity and usage appropriateness.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS8875249B2Minimum lifespan credentials for crawling data repositories
Publication Date: 2014.10.28 ORACLE INT CORP
  • US8875249B2 patent drawing
  • US8875249B2 patent drawing
  • US8875249B2 patent drawing

AI summary

A flexible and extensible architecture allows for secure searching across an enterprise. Such an architecture can provide a simple Internet-like search experience to users searching secure content inside (and outside) the enterprise. The architecture allows for the crawling and searching of a variety of sources across an enterprise, regardless of whether any of these sources conform to a conventional user role model. The architecture further allows for security attributes to be submitted at query time, for example, in order to provide real-time secure access to enterprise resources. The user query also can be transformed to provide for dynamic querying that provides for a more current result list than can be obtained for static queries.