Hierarchical Domain Access Control for Fixed-Value Attributes

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing access control systems face challenges in managing access to objects with attributes defined against hierarchically organized domains containing a fixed number of values, particularly in large-scale financial applications where precise control over access based on attribute values is necessary.

Innovation Solution

The system enables administrators to select desired sets of values from hierarchically organized domains and specify security rules for user entities, enforcing these rules by displaying a Cartesian product of values and user entities, and appending conditions to SQL queries to control access effectively.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If traditional access control systems are used for objects with hierarchically organized domain attributes, then basic access control is provided, but the system becomes complex and difficult to manage when dealing with large numbers of objects and hierarchical domains

Engineering Contradiction:
Improveaccess control managementVSAvoidaccess control system complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent segments the access control system into hierarchical domains (e.g., country, state, city) where each domain level can be independently configured and managed. This allows administrators to control access at different levels of the hierarchy without managing every individual object, thereby reducing operational complexity while maintaining granular control capabilities

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates universal access control rules that can apply across multiple objects sharing common attribute patterns. By defining rules at the domain level rather than individual object level, the system provides multi-functional access control that works across diverse objects with hierarchical attributes, simplifying management while maintaining precision

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If granular access control rules are applied to each object individually, then precise access control is achieved, but the time and resources required to manage access control increase significantly

Engineering Contradiction:
Improveaccess control precisionVSAvoidaccess control management time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent enables administrators to pre-define access control rules at the hierarchical domain level before objects are created or accessed. These preliminary rules automatically apply to objects matching the domain criteria, eliminating the need to configure access control for each object individually and significantly reducing management time while maintaining precise control

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent allows access control rules to be copied and reused across multiple domain levels and object types. Once a rule is defined at one level of the hierarchy, it can be replicated to other levels or similar domains, reducing the time required to establish consistent access control policies across the entire system

Inventive Principle:
Principle #26Copying

Data Source

PatentUS10645090B2Access control for objects having attributes defined against hierarchically organized domains containing fixed number of values
Publication Date: 2020.05.05 ORACLE FINANCIAL SERVICES SOFTWARE
  • US10645090B2 patent drawing
  • US10645090B2 patent drawing
  • US10645090B2 patent drawing

AI summary

An aspect of the present disclosure facilitates controlling access to objects having attributes defined against hierarchically organized domains, with each domain containing a corresponding fixed number of values. In one embodiment, in response to receiving data indicating specific hierarchies of the hierarchically organized domains, the corresponding fixed number of values of the corresponding domains in each hierarchy is displayed. Accordingly, a user is enabled to select a desired set of values from the corresponding fixed number of values of the corresponding domains, and to specify a security rule for a combination of the selected set of values and a user entity. The security rule is thereafter enforced when objects having attributes matching the selected set of values are accessed by the user entity.