Externalized Entitlement Management System for Cross-Application Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing entitlement management systems are often application-specific and incompatible, making it difficult to manage access across different networked resources and applications, particularly between systems like Oracle RDBMS and Microsoft Exchange Server, leading to fragmented and inefficient access control.
Innovation Solution
An externalized entitlement management system with a Policy Administration Point (PAP) for centralized policy definition, coupled with Policy Decision Points (PDPs) and Policy Enforcement Points (PEPs) that provide hybrid policy resolution and enforcement across diverse applications, enabling scalable and fine-grained distributed entitlement management.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If entitlement management is implemented within individual application programs, then each application can maintain its own security logic, but the systems become incompatible and inaccessible to other applications and servers
Solution Approach 1:
The patent implements a universal entitlement management system that serves multiple applications and servers through a common interface. The system translates application-specific security requests into standardized entitlement evaluations, enabling Oracle RDBMS, Microsoft Exchange Server, and other diverse systems to participate in a unified entitlement framework while maintaining their individual security requirements.
Solution Approach 2:
The patent introduces an intermediary entitlement management layer between applications and users. This intermediary translates application-specific authentication and authorization requests into standardized entitlement evaluations, allowing incompatible systems to interoperate through a common entitlement language without requiring direct integration between each application pair.
2Adaptability or versatility
If centralized policy management is implemented across diverse applications, then cross-application access control is achieved, but the complexity of managing incompatible security mechanisms increases
Solution Approach 1:
The patent segments the entitlement management system into distinct functional components: policy definition, entitlement evaluation, and application integration. Each application integrates only with the standardized entitlement interface, while the system handles the complexity of translating between different application-specific security mechanisms and the unified entitlement model.
Solution Approach 2:
The patent transforms application-specific security parameters into standardized entitlement parameters. The system maps diverse authentication and authorization requirements from different applications into a common entitlement language, enabling centralized management without requiring each application to accommodate every other application's specific security mechanisms.
3Reliability
If application-specific authentication systems are used, then each system can control access independently, but the systems become inaccessible to other network resources and application servers
Solution Approach 1:
The patent creates a universal entitlement evaluation service that handles authentication and authorization requests from multiple application-specific systems. Users can access resources across Oracle RDBMS, Microsoft Exchange Server, and other applications through a unified entitlement evaluation process that respects each system's authentication requirements while providing consistent cross-system access control.
Data Source
AI summary
An externalized entitlement management system comprises a policy administration point that is configured to receive one or more definitions or updates of entitlement policies specifying subjects, actions, and resources, and to update a first entitlement repository coupled to the policy administration point with the definitions or updates in response to receiving the definitions or updates; one or more policy decision points that are coupled to the policy administration point over a network; one or more policy enforcement points that are integrated into one or more respective first application programs, wherein each of the policy enforcement points is coupled to one of the policy decision points; and one or more action handlers in the policy administration point, wherein each of the action handlers is configured to intercept a particular action represented in an update to an entitlement policy, to transform the action into an entitlement update in a form compatible with a native entitlement mechanism of a second application program that does not have one of the policy enforcement points, to send the transformed entitlement update to the second application program, and to cause a rollback of the update of the first entitlement repository if the second application program fails to implement the entitlement update in the native entitlement mechanism.


