Database Role Optimization System
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Customers face complexity in managing numerous roles and authorizations provided by vendors, leading to redundant and unused permissions, which complicates administration and increases maintenance burdens.
Innovation Solution
A role optimization system that analyzes user activity to aggregate vendor roles and authorizations, creating a single customer role with only the permissions actually used, reducing the number of roles and authorizations assigned to users.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If vendor roles with comprehensive authorizations are provided to customers, then complete access control coverage is achieved, but role management complexity increases significantly
Solution Approach 1:
The system merges multiple vendor roles into a single customized customer role by analyzing user activity patterns and consolidating necessary authorizations. This combines the comprehensive coverage of multiple roles while eliminating the complexity of managing them separately, creating one optimized role that maintains security while simplifying administration.
Solution Approach 2:
The system extracts only the authorizations that are actually used by users from the comprehensive vendor roles. By analyzing executable usage patterns and identifying which authorizations are genuinely needed, the system removes unnecessary permissions while retaining complete coverage of required access control, thereby reducing role complexity.
2Reliability
If multiple vendor roles are assigned to users to provide necessary permissions, then complete authorization coverage is achieved, but administrative overhead increases
Solution Approach 1:
The system combines multiple vendor roles into a single customized role that provides equivalent authorization coverage. This merging eliminates the need for administrators to manage multiple separate role assignments, reducing administrative overhead while maintaining complete authorization coverage through the consolidated role.
Solution Approach 2:
The system automatically analyzes user activity patterns and generates optimized roles without requiring manual administrative intervention. This self-service approach reduces administrative overhead by eliminating time-consuming manual role configuration, while still achieving complete authorization coverage through automated analysis of actual user needs.
3Reliability
If comprehensive vendor roles with many authorizations are provided, then complete access control is ensured, but system performance decreases due to processing overhead
Solution Approach 1:
The system extracts and retains only the authorizations that are actually used by users, removing unnecessary permissions from the role configuration. This reduction in the number of authorizations decreases the processing overhead during access control checks while maintaining complete security coverage for all required operations, thereby improving system performance.
4Adaptability or versatility
If vendor roles are copied into customer namespace with all authorizations, then complete role functionality is preserved, but maintenance burden increases during updates
Solution Approach 1:
The system merges the functionality of multiple vendor roles into a single customized customer role. This consolidation maintains complete role functionality while simplifying maintenance, as updates only need to be applied to one consolidated role rather than managing updates across multiple separate vendor roles, thereby reducing the maintenance burden.
Data Source
AI summary
Particular embodiments provide a system that analyzes and optimizes roles and authorizations for users of a customer. The system determines which executables have been used by users in the system over a certain time period. Thereafter, the system analyzes and optimizes authorizations within the assigned roles for the users. The authorizations for the roles assigned to the user are then analyzed. The vendor roles typically have redundant authorizations, some of which may be used and some not used. The system can then generate a new customer role for the user with the used authorizations combined into the new role. For example, the authorizations used by the user are combined into the new customer role. This reduces the number of roles the user has assigned to him/her, and also the number of authorizations. Also, the new customer role may be added to other users with the same role at the customer.


