Hierarchical IT Access Control Interface for Cloud Platforms

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

System administrators face inefficiencies when reviewing user-accessible and user-inaccessible lists to address user issues with accessing catalog items in cloud-based IT platforms, as the process is tedious and time-consuming.

Innovation Solution

A control system that allows entry of a user and a catalog item, displaying a visual representation of the categorized hierarchy with accessibility indications, enabling access modification through user groupings, allowing administrators to easily manage user access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If system administrators manually review user-accessible and user-inaccessible lists to address user access issues, then user access problems can be identified and resolved, but the process becomes tedious and time-consuming

Engineering Contradiction:
Improveuser access issue resolutionVSAvoidadministrator time consumption
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent segments the complex user access management task into distinct hierarchical components: catalog items, categories, and user groupings. This segmentation allows administrators to systematically review access controls at each level rather than manually checking every user-item combination, significantly reducing time consumption while maintaining reliable issue resolution

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a hierarchical dimension to user access management by organizing catalog items into categorized hierarchies and users into groupings. This dimensional organization transforms the flat, tedious review process into a structured multi-level analysis, enabling administrators to efficiently identify and resolve access issues by navigating through hierarchical levels rather than examining individual user-item pairs

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Ease of operation

If detailed user-accessible and user-inaccessible lists are maintained for each catalog entity, then user accessibility can be precisely controlled, but the complexity of managing these lists increases

Engineering Contradiction:
Improveuser accessibility controlVSAvoidaccess management system complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent applies universality by creating user groupings that can be assigned to multiple catalog entities and categories simultaneously. A single user grouping can control access across entire hierarchical branches, eliminating the need to manage separate access lists for each individual item. This multi-functional approach simplifies access control while maintaining precise granularity where needed

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent implements nesting by organizing catalog entities into hierarchical categories that contain sub-categories and items. User groupings are nested within this hierarchy, allowing administrators to assign access rights at any level and have those rights automatically propagate to nested levels. This nested structure reduces management complexity by allowing control at higher levels rather than managing each individual element separately

Inventive Principle:
Principle #7Nested doll (Nesting)

Data Source

PatentUS11363030B2Systems and methods for categorized hierarchical view and modification of user accessibility to information technology item
Publication Date: 2022.06.14 SERVICENOW INC
  • US11363030B2 patent drawing
  • US11363030B2 patent drawing
  • US11363030B2 patent drawing

AI summary

The present disclosure includes systems and methods that provide a control that enables entry of a user and a catalog item. In response to this entry, a visual representation of the categorized hierarchy of the catalog item and categories (collectively “catalog entities”) to which the catalog item belongs are displayed. Each displayed catalog entity may include a visual indication of whether the catalog entity is accessible to the user. In some embodiments, the displayed catalog entity may include a control that enables or disables access to the catalog entity. The displayed catalog entity may also include a control that displays user groupings that have access or do not have access to that displayed catalog entity. An indication of whether the user belongs to each user grouping may also be displayed. Each displayed user group may include a control that enables modification to the definition of the displayed user grouping.