Group Management Engine for Entitlement Provisioning

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current IT infrastructure is complex, inflexible, and expensive to manage, especially in large organizations with diverse access devices and frequent software updates required for security, making it difficult to efficiently and securely grant access to computer resources.

Innovation Solution

An Entitlement Management System (EMS) that includes a Group Management Engine, Entitlement Engine, and Provisioning Engine to manage group membership and entitlements in real-time, automatically updating access to computer resources based on user roles and changes, independent of device or resource type.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If traditional PC locking and software pushing approaches are used, then device security and software distribution are maintained, but the system cannot handle frequent real-time updates and diverse access devices

Engineering Contradiction:
Improvesupport for diverse access devices and frequent updatesVSAvoidcomplexity of PC configuration and update management
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces a server as an intermediary between administrators and access devices. The server receives update instructions, stores them, and distributes them to authorized devices. This intermediary architecture allows frequent real-time updates to be pushed to diverse devices (PCs, laptops, PDAs, mobile phones) without requiring complex local configuration management on each device, resolving the contradiction between adaptability and complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If separate infrastructure is used for each application platform, then platform-specific requirements are met, but system complexity and management overhead increase

Engineering Contradiction:
Improvesupport for multiple application platformsVSAvoidinfrastructure complexity for managing multiple platforms
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements a universal server infrastructure that can handle multiple application platforms (local applications, terminal applications, thin clients, web services, virtual machines) through a single system. The server provides platform-agnostic update distribution and entitlement management, eliminating the need for separate infrastructure for each platform type while still meeting specific platform requirements, thus resolving the contradiction between versatility and complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If manual access control management is used, then security policies can be enforced, but administrative overhead and time consumption increase significantly

Engineering Contradiction:
Improveaccess control securityVSAvoidadministrative efficiency in managing access rights
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements automatic entitlement management where the server autonomously determines access rights based on user roles and group memberships. When a user's role changes or they are added to a group, the server automatically updates their access entitlements without requiring manual administrator intervention for each change. This self-service automation maintains security policies while dramatically improving administrative efficiency, resolving the contradiction between reliability and productivity.

Inventive Principle:
Principle #25Self-service

4Reliability

If group membership updates are not synchronized in real-time, then system performance is maintained, but access control accuracy and security are compromised

Engineering Contradiction:
Improveaccess control accuracyVSAvoiddelay in updating access rights
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements a feedback mechanism where the server continuously monitors group membership changes and user role modifications. When changes are detected, the server automatically triggers entitlement updates and pushes notifications to affected devices in real-time. This continuous feedback loop ensures access control accuracy is maintained without significant time delays, resolving the contradiction between reliability and time loss.

Inventive Principle:
Principle #23Feedback

Data Source

PatentEP2705459B1Dynamic management of groups for entitlement and provisioning of computer resources
Publication Date: 2020.08.05 VMWARE INC
  • EP2705459B1 patent drawingFigure 1
  • EP2705459B1 patent drawingFigure 2
  • EP2705459B1 patent drawingFigure 3

AI summary

Methods, systems, and techniques for managing groups of entities, such as individuals, employees, or systems, and providing entitlement and access to computer resources based on group membership are provided. Example embodiments provide a Group Management System having a Group Management Engine "GME," an Entitlement Engine, and a Provisioning Engine, which work together to allow simplified grouping of entities and providing entitlement and access to the entities based upon the group membership. In one embodiment, the GME leverages dynamic programming techniques to enable accurate, scalable systems that can manage near real time updates and changes to the group's status or to the entities' status. These components cooperate to enable provisioning of applications based upon current entitlement.