Integrating Enterprise Data Warehouse and BPC Authorizations

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current data warehouse authorization systems require centralized IT departments to manage authorizations for multiple lines of business, leading to inefficiencies and delays, as local IT departments must wait for centralized approval for user-specific customizations.

Innovation Solution

Implementing a system that integrates enterprise data warehouse authorizations with environment authorizations and user-based data access profiles, allowing local IT departments to define and configure authorizations independently, while ensuring compliance with centralized frameworks, thus decentralizing the authorization process.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If centralized IT departments manage all authorizations, then security and compliance are maintained, but authorization configuration time and local responsiveness deteriorate

Engineering Contradiction:
Improveauthorization complianceVSAvoidauthorization configuration time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The authorization management system is segmented into centralized and local components. Centralized IT departments define framework authorizations and security policies, while local IT departments can independently configure user-specific authorizations within the framework. This segmentation allows local departments to respond quickly to business needs without requiring centralized approval for each authorization change.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Centralized IT departments prepare and publish framework authorizations in advance that define the structure and security requirements. Local IT departments then use these pre-defined frameworks to quickly configure user authorizations without needing real-time centralized approval, reducing configuration time while maintaining compliance.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If centralized IT departments approve all authorizations, then security standards are maintained, but local IT department autonomy and productivity deteriorate

Engineering Contradiction:
Improvesecurity complianceVSAvoidlocal IT department efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

Authorization management is divided into two segments: centralized framework definition and local user-specific configuration. Local IT departments gain autonomy to configure authorizations independently within the security framework, improving their productivity while centralized control maintains security compliance through the predefined framework.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system allows local IT departments to customize authorizations according to their specific business needs and user requirements while adhering to the centralized security framework. This local quality approach enables local departments to be more efficient and responsive without compromising overall security standards.

Inventive Principle:
Principle #3Local quality

3Speed

If local IT departments configure authorizations independently, then configuration speed improves, but authorization consistency and compliance control worsen

Engineering Contradiction:
Improveauthorization configuration speedVSAvoidauthorization consistency
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

Centralized IT departments prepare framework authorizations that define the structure, permissions, and security requirements in advance. Local IT departments then use these pre-established frameworks to configure user authorizations quickly and consistently, ensuring that speed does not compromise authorization consistency or compliance.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The framework authorizations serve multiple functions: they provide the structural template for consistent authorization design, enforce security compliance, and enable local departments to configure user-specific permissions efficiently. This multi-functionality allows the system to achieve both speed and consistency simultaneously.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9391973B2Integration of centralized and local authorizations for multi-dimensional data
Publication Date: 2016.07.12 SAP SE
  • US9391973B2 patent drawing
  • US9391973B2 patent drawing
  • US9391973B2 patent drawing

AI summary

The present disclosure describes methods, systems, and computer program products for integrating authorizations. One computer-implemented method includes: reading enterprise data warehouse (EDW) authorizations for a user from an authorization database in response to a query generated by the user for EDW data; responsive to a determination that the user is assigned to an environment, reading environment authorizations from a business planning and consolidation (BPC) system; enhancing the EDW authorizations for the user with the environment authorizations read from the BPC system to create a new authorization set; reading a user-based data access profile (DAP) from the BPC; and intersecting the new authorization set with the DAP to create an overall user authorization set.