Enterprise Search Security via Dynamic Query-Time Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing search systems face challenges in securely accessing and indexing content across enterprise applications with dynamic security hierarchies, as they lack the ability to handle varying security attributes and user roles that change frequently, leading to complications in authentication and authorization processes.

Innovation Solution

A flexible and extensible architecture that enables secure enterprise search by authenticating users through a flexible framework, submitting security attributes at query time, and using identity management systems to manage dynamic security access, allowing for real-time access to secure resources and providing suggested content and links relevant to user queries.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a crawler is programmed to be aware of all security requirements of each application or source, then secure access to enterprise data is achieved, but the crawling process becomes drastically complicated and slows down

Engineering Contradiction:
Improvesecure accessVSAvoidcrawling process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary authentication framework that mediates between the crawler and enterprise applications. This framework includes authentication modules, identity management systems, and standardized protocols that handle security requirements centrally rather than requiring the crawler to be programmed with application-specific security knowledge. The intermediary layer translates and manages security attributes, reducing crawling process complexity while maintaining secure access.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates a universal authentication framework that can handle multiple enterprise applications and data sources through standardized protocols. The identity management system and authentication modules are designed to be application-agnostic, providing multi-functional security management that works across different applications without requiring application-specific customization, thereby reducing crawler complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Productivity

If security attributes are managed statically during crawling, then crawling performance is maintained, but dynamic security hierarchies and user roles cannot be accommodated

Engineering Contradiction:
Improvecrawling performanceVSAvoiddynamic security handling
Core Design Contradiction:
ProductivityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic security attribute management where security attributes are not fixed during crawling but are retrieved and evaluated in real-time based on user identity and context. The authentication framework dynamically determines access permissions by querying identity management systems during the crawling process, allowing the system to adapt to changing security hierarchies and user roles while maintaining acceptable performance through efficient query mechanisms.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent performs preliminary authentication and security attribute retrieval before the actual crawling operation. By establishing user identity and security context in advance, the system prepares necessary authentication tokens and security attributes that can be reused during crawling, reducing the performance impact of dynamic security checks while maintaining adaptability to security changes.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If authentication and authorization are performed for each data source, then authorized access is ensured, but the authentication process becomes complicated and time-consuming

Engineering Contradiction:
Improveauthorized accessVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent merges authentication and authorization functions into a unified authentication framework that handles both security concerns in a single integrated process. The identity management system combines user identification, authentication, and authorization attribute retrieval into one coordinated workflow, eliminating the need for separate authentication and authorization steps for each data source, thereby reducing total authentication time while ensuring authorized access.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent implements feedback mechanisms where the authentication framework learns from previous authentication outcomes and optimizes subsequent authentication operations. The system uses feedback from identity management systems to cache authentication results, adjust security attribute retrieval strategies, and optimize the authentication workflow based on observed patterns, reducing authentication time for repeated operations while maintaining security.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS8005816B2Auto generation of suggested links in a search system
Publication Date: 2011.08.23 ORACLE INT CORP
  • US8005816B2 patent drawing
  • US8005816B2 patent drawing
  • US8005816B2 patent drawing

AI summary

A flexible and extensible architecture allows for secure searching across an enterprise. Such an architecture can provide a simple Internet-like search experience to users searching secure content inside (and outside) the enterprise. The architecture allows for the crawling and searching of a variety of sources across an enterprise, regardless of whether any of these sources conform to a conventional user role model. The architecture further allows for security attributes to be submitted at query time, for example, in order to provide real-time secure access to enterprise resources. The user query also can be transformed to provide for dynamic querying that provides for a more current result list than can be obtained for static queries.