Database Role Optimization System

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Customers face complexity in managing numerous roles and authorizations provided by vendors, leading to redundant and unused permissions, which complicates administration and increases maintenance burdens.

Innovation Solution

A role optimization system that analyzes user activity to aggregate vendor roles and authorizations, creating a single customer role with only the permissions actually used, reducing the number of roles and authorizations assigned to users.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If vendor roles with comprehensive authorizations are provided to customers, then complete access control coverage is achieved, but role management complexity increases significantly

Engineering Contradiction:
Improveaccess control coverageVSAvoidrole management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system merges multiple vendor roles into a single customized customer role by analyzing user activity patterns and consolidating necessary authorizations. This combines the comprehensive coverage of multiple roles while eliminating the complexity of managing them separately, creating one optimized role that maintains security while simplifying administration.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system extracts only the authorizations that are actually used by users from the comprehensive vendor roles. By analyzing executable usage patterns and identifying which authorizations are genuinely needed, the system removes unnecessary permissions while retaining complete coverage of required access control, thereby reducing role complexity.

Inventive Principle:
Principle #2Taking out (Extraction)

2Reliability

If multiple vendor roles are assigned to users to provide necessary permissions, then complete authorization coverage is achieved, but administrative overhead increases

Engineering Contradiction:
Improveauthorization coverageVSAvoidadministrative overhead
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system combines multiple vendor roles into a single customized role that provides equivalent authorization coverage. This merging eliminates the need for administrators to manage multiple separate role assignments, reducing administrative overhead while maintaining complete authorization coverage through the consolidated role.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system automatically analyzes user activity patterns and generates optimized roles without requiring manual administrative intervention. This self-service approach reduces administrative overhead by eliminating time-consuming manual role configuration, while still achieving complete authorization coverage through automated analysis of actual user needs.

Inventive Principle:
Principle #25Self-service

3Reliability

If comprehensive vendor roles with many authorizations are provided, then complete access control is ensured, but system performance decreases due to processing overhead

Engineering Contradiction:
Improveaccess control securityVSAvoidsystem performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system extracts and retains only the authorizations that are actually used by users, removing unnecessary permissions from the role configuration. This reduction in the number of authorizations decreases the processing overhead during access control checks while maintaining complete security coverage for all required operations, thereby improving system performance.

Inventive Principle:
Principle #2Taking out (Extraction)

4Adaptability or versatility

If vendor roles are copied into customer namespace with all authorizations, then complete role functionality is preserved, but maintenance burden increases during updates

Engineering Contradiction:
Improverole functionalityVSAvoidmaintenance ease
Core Design Contradiction:
Adaptability or versatilityVSEase of manufacture

Solution Approach 1:

The system merges the functionality of multiple vendor roles into a single customized customer role. This consolidation maintains complete role functionality while simplifying maintenance, as updates only need to be applied to one consolidated role rather than managing updates across multiple separate vendor roles, thereby reducing the maintenance burden.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS9842221B2Role analyzer and optimizer in database systems
Publication Date: 2017.12.12 SAP SE
  • US9842221B2 patent drawing
  • US9842221B2 patent drawing
  • US9842221B2 patent drawing

AI summary

Particular embodiments provide a system that analyzes and optimizes roles and authorizations for users of a customer. The system determines which executables have been used by users in the system over a certain time period. Thereafter, the system analyzes and optimizes authorizations within the assigned roles for the users. The authorizations for the roles assigned to the user are then analyzed. The vendor roles typically have redundant authorizations, some of which may be used and some not used. The system can then generate a new customer role for the user with the used authorizations combined into the new role. For example, the authorizations used by the user are combined into the new customer role. This reduces the number of roles the user has assigned to him/her, and also the number of authorizations. Also, the new customer role may be added to other users with the same role at the customer.