Enterprise Entitlement Framework for Flexible Privilege Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current privilege management systems, such as those using Lightweight Directory Access Protocol (LDAP) solutions, require significant programming and reconfiguration when new applications or databases are added or updated, lacking flexibility and extensibility to manage privilege information across multiple applications and databases effectively.

Innovation Solution

A flexible and extensible enterprise entitlement framework is introduced, utilizing various data structures and objects like resource type, action, role, user, and rule objects to represent and store privilege components, allowing for user-based or role-based management, with features like privilege cascades and maintenance objects for auditing and reporting, enabling adaptive privilege management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If LDAP solutions are used to manage privilege information across multiple applications, then centralized control of privilege data is achieved, but significant programming and reconfiguration are required when new applications or databases are added or updated

Engineering Contradiction:
Improveflexibility to accommodate new applicationsVSAvoidprogramming and reconfiguration requirements
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements a universal privilege management framework using standardized data structures (LDAP-compatible formats) that can serve multiple applications and databases through a common interface. The framework defines universal object classes and attributes that work across different application types, eliminating the need for application-specific programming when adding new systems.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent segments the privilege management system into independent, modular components including object classes, attributes, and operations that can be individually configured and extended. This segmentation allows new applications to be integrated by defining only their specific attributes and object classes without modifying the core framework, reducing reconfiguration requirements.

Inventive Principle:
Principle #1Segmentation

2Stability of the object's composition

If LDAP solutions are used for privilege management, then existing privilege structures can be maintained, but the system lacks flexibility when applications are updated or reconfigured

Engineering Contradiction:
Improvemaintenance of existing privilege structuresVSAvoidadaptability to application updates
Core Design Contradiction:
Stability of the object's compositionVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic privilege management where the LDAP structure can adapt to application changes through configurable object classes and attributes. The system allows runtime modification of privilege definitions and mappings without requiring structural changes to the core LDAP framework, enabling both stability of existing structures and adaptability to updates.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent utilizes parameter-based configuration where privilege structures are defined through modifiable parameters (attributes and object classes) rather than fixed code. This allows existing privilege structures to be maintained while enabling flexible parameter changes when applications are updated, separating structural stability from configurational flexibility.

Inventive Principle:
Principle #35Parameter changes

3Extent of automation

If traditional privilege management systems are used, then centralized control is achieved, but manual reconfiguration is required for each new privilege type or resource

Engineering Contradiction:
Improveautomation of privilege managementVSAvoidmanual reconfiguration time
Core Design Contradiction:
Extent of automationVSLoss of time

Solution Approach 1:

The patent implements self-service automation where the privilege management system automatically handles configuration tasks through standardized LDAP operations. When new applications or resources are added, the system automatically creates appropriate object classes and attributes based on predefined templates, eliminating manual reconfiguration and reducing administrative time.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS8931055B2Enterprise entitlement framework
Publication Date: 2015.01.06 ACCENTURE GLOBAL SERVICES LTD
  • US8931055B2 patent drawing
  • US8931055B2 patent drawing
  • US8931055B2 patent drawing

AI summary

A method and system for managing privilege information across multiple applications and/or databases is provided. A flexible and extensible enterprise entitlement framework may be implemented to store and manage various types of privileges, access rights and resources. The enterprise entitlement framework may include a variety of data objects and structures configured to store various components and/or aspects of a privilege. The data objects may include resource type objects, user objects, role objects, action objects, resource attribute objects, list item object and/or hierarchy objects. The data objects defined for a particular privilege may further be linked according to relationships between one or more objects. The enterprise entitlement framework is extensible for use with new applications by defining new objects compatible with the privilege structures of the new applications.