Externalized Entitlement Management System for Cross-Application Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing entitlement management systems are often application-specific and incompatible, making it difficult to manage access across different networked resources and applications, particularly between systems like Oracle RDBMS and Microsoft Exchange Server, leading to fragmented and inefficient access control.

Innovation Solution

An externalized entitlement management system with a Policy Administration Point (PAP) for centralized policy definition, coupled with Policy Decision Points (PDPs) and Policy Enforcement Points (PEPs) that provide hybrid policy resolution and enforcement across diverse applications, enabling scalable and fine-grained distributed entitlement management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If entitlement management is implemented within individual application programs, then each application can maintain its own security logic, but the systems become incompatible and inaccessible to other applications and servers

Engineering Contradiction:
Improveapplication-specific security controlVSAvoidcross-application access compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements a universal entitlement management system that serves multiple applications and servers through a common interface. The system translates application-specific security requests into standardized entitlement evaluations, enabling Oracle RDBMS, Microsoft Exchange Server, and other diverse systems to participate in a unified entitlement framework while maintaining their individual security requirements.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent introduces an intermediary entitlement management layer between applications and users. This intermediary translates application-specific authentication and authorization requests into standardized entitlement evaluations, allowing incompatible systems to interoperate through a common entitlement language without requiring direct integration between each application pair.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If centralized policy management is implemented across diverse applications, then cross-application access control is achieved, but the complexity of managing incompatible security mechanisms increases

Engineering Contradiction:
Improveenterprise-wide entitlement managementVSAvoidpolicy integration complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the entitlement management system into distinct functional components: policy definition, entitlement evaluation, and application integration. Each application integrates only with the standardized entitlement interface, while the system handles the complexity of translating between different application-specific security mechanisms and the unified entitlement model.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent transforms application-specific security parameters into standardized entitlement parameters. The system maps diverse authentication and authorization requirements from different applications into a common entitlement language, enabling centralized management without requiring each application to accommodate every other application's specific security mechanisms.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If application-specific authentication systems are used, then each system can control access independently, but the systems become inaccessible to other network resources and application servers

Engineering Contradiction:
Improveauthentication controlVSAvoidcross-system resource access
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent creates a universal entitlement evaluation service that handles authentication and authorization requests from multiple application-specific systems. Users can access resources across Oracle RDBMS, Microsoft Exchange Server, and other applications through a unified entitlement evaluation process that respects each system's authentication requirements while providing consistent cross-system access control.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS8010991B2Policy resolution in an entitlement management system
Publication Date: 2011.08.30 CISCO TECHNOLOGY INC
  • US8010991B2 patent drawing
  • US8010991B2 patent drawing
  • US8010991B2 patent drawing

AI summary

An externalized entitlement management system comprises a policy administration point that is configured to receive one or more definitions or updates of entitlement policies specifying subjects, actions, and resources, and to update a first entitlement repository coupled to the policy administration point with the definitions or updates in response to receiving the definitions or updates; one or more policy decision points that are coupled to the policy administration point over a network; one or more policy enforcement points that are integrated into one or more respective first application programs, wherein each of the policy enforcement points is coupled to one of the policy decision points; and one or more action handlers in the policy administration point, wherein each of the action handlers is configured to intercept a particular action represented in an update to an entitlement policy, to transform the action into an entitlement update in a form compatible with a native entitlement mechanism of a second application program that does not have one of the policy enforcement points, to send the transformed entitlement update to the second application program, and to cause a rollback of the update of the first entitlement repository if the second application program fails to implement the entitlement update in the native entitlement mechanism.