Enterprise Search Intermediary for Dynamic Security Attribute Submission

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing search systems face challenges in securely accessing and indexing content across enterprise applications with dynamic security hierarchies, as they lack the ability to handle varying security attributes and user roles that change frequently, leading to complications in authentication and authorization processes.

Innovation Solution

A flexible and extensible architecture that enables secure enterprise search by authenticating users through a flexible framework, submitting security attributes at query time, and using identity management systems to manage dynamic user permissions, allowing for real-time access to secure resources and providing suggested content relevant to user queries.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a crawler is programmed to be aware of all security requirements of each application or source, then secure access to enterprise data is improved, but the crawling process becomes drastically complicated and slow

Engineering Contradiction:
Improvesecure accessVSAvoidcrawling process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary component that acts as a bridge between the crawler and secured data sources. This intermediary handles authentication and authorization by obtaining credentials and security attributes, allowing the crawler to access protected resources without being programmed with complex security requirements for each individual application. The intermediary resolves the contradiction by centralizing security management externally rather than embedding it within the crawling process itself.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If a crawler is programmed to authenticate and authorize users across multiple systems, then access control is improved, but the crawling process becomes drastically complicated and slow

Engineering Contradiction:
Improveaccess controlVSAvoidcrawling speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies preliminary action by obtaining security credentials and user authorization status before the crawling process begins. The system retrieves authentication tokens, user profiles, and security attributes in advance, storing them for use during crawling operations. This preliminary preparation eliminates the need for repeated authentication handshakes during the crawl, thereby maintaining strict access control while significantly improving crawling speed and productivity.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If security attributes are managed dynamically for each user query, then user-specific secure access is improved, but system complexity increases

Engineering Contradiction:
Improveuser-specific accessVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements self-service by enabling the system to automatically retrieve and manage security attributes dynamically during query processing. When a user submits a query, the system autonomously obtains the user's security credentials, determines authorized data sources, and applies appropriate access controls without requiring manual configuration or complex administrative intervention. This self-service approach provides tailored secure access for each user while keeping system complexity manageable through automation.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS8868540B2Method for suggesting web links and alternate terms for matching search queries
Publication Date: 2014.10.21 ORACLE INT CORP
  • US8868540B2 patent drawing
  • US8868540B2 patent drawing
  • US8868540B2 patent drawing

AI summary

A flexible and extensible architecture allows for secure searching across an enterprise. Such an architecture can provide a simple Internet-like search experience to users searching secure content inside (and outside) the enterprise. The architecture allows for the crawling and searching of a variety of sources across an enterprise, regardless of whether any of these sources conform to a conventional user role model. The architecture further allows for security attributes to be submitted at query time, for example, in order to provide real-time secure access to enterprise resources. The user query also can be transformed to provide for dynamic querying that provides for a more current result list than can be obtained for static queries.