Hierarchical Role-Based Authorization System for Delegated Administration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing authorization systems for enterprise applications are complex and time-consuming to implement and maintain, especially when closely tied to business logic, making it difficult to manage resource access and privileges effectively.

Innovation Solution

A hierarchical role-based authorization system that uses dynamic role expressions and security policies to evaluate entitlements, allowing for flexible and efficient management of resource access by associating roles with principals based on context information, and enabling delegation of administrative capabilities through a role hierarchy.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If authorization systems are closely tied to business logic in enterprise applications, then authorization control can be precisely integrated with business processes, but the system becomes complex and time-consuming to implement and maintain

Engineering Contradiction:
Improveauthorization control precisionVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces role expressions as an intermediary layer between principals and authorization policies. Instead of directly tying authorization to business logic, role expressions serve as a mediator that evaluates contextual information and determines role membership, thereby simplifying the authorization system while maintaining precise control integration with business processes

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the authorization system into distinct components: principals, role expressions, roles, and authorization policies. This segmentation allows each component to be independently managed and evaluated, reducing overall system complexity while enabling precise authorization control through the coordinated operation of these modular elements

Inventive Principle:
Principle #1Segmentation

2Reliability

If traditional authorization systems are implemented, then resource access control can be established, but the systems are difficult to manage and maintain

Engineering Contradiction:
Improveresource access controlVSAvoidmanagement ease
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements dynamic role expressions that are evaluated at runtime based on contextual information about the principal and the requested resource. This dynamic evaluation allows the authorization system to adapt to changing conditions without requiring manual reconfiguration, making the system easier to manage while maintaining secure resource access control

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The authorization system automatically evaluates role expressions and determines authorization decisions without requiring manual intervention for each access request. The system self-manages the complex evaluation logic through automated role expression evaluation, reducing the administrative burden while ensuring proper resource access control

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS7774601B2Method for delegated administration
Publication Date: 2010.08.10 ORACLE INT CORP
  • US7774601B2 patent drawing
  • US7774601B2 patent drawing
  • US7774601B2 patent drawing

AI summary

A system and method for providing a containment model of role capabilities wherein a parent role can obtain the capabilities of its child role(s).