Hierarchical Role-Based Access Control for Enterprise Systems

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing role-based access control (RBAC) systems face challenges in managing access entitlements across multiple business domains in large enterprises, particularly in complex operational environments, and fail to preserve the enterprise perspective, leading to inefficiencies and inaccuracies in authorization and resource management.

Innovation Solution

A system and method that utilizes a provisioning unit to manage role-based access control by viewing authorization rights as a mosaic, associating users with provisioning units based on attributes, and mapping application roles within an application registry module, allowing for the integration of access control across heterogeneous environments and preserving enterprise goals.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a central role server or LDAP directory structure is used to manage entitlements, then centralized control and retrieval of user permissions is achieved, but operational complexity increases and scalability deteriorates in large enterprises with complex operation patterns

Engineering Contradiction:
Improvecentralized controlVSAvoidoperational complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the centralized role server into multiple distributed role servers organized in a hierarchical structure. Each role server manages entitlements for a specific organizational unit or business domain, eliminating the single-point complexity of a central server while maintaining centralized control through hierarchical coordination.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a hierarchical dimension to the role server architecture, organizing role servers across multiple levels (enterprise-level, business unit-level, department-level). This dimensional transformation allows centralized control to be distributed across hierarchical layers, reducing operational complexity at any single level while maintaining enterprise-wide consistency.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Ease of operation

If resource consumption groups are used for authorization, then group-based rights management is simplified, but intuitiveness deteriorates when numbers of groups grow beyond certain size and enterprise organizational perspective is lost

Engineering Contradiction:
Improvegroup-based managementVSAvoidnumber of groups
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent segments the flat group structure into hierarchical organizational units that mirror the enterprise structure. Instead of creating numerous flat groups, the system creates hierarchical units (enterprise → business units → departments → teams) that naturally organize users and resources, reducing the perceived complexity as the organization grows.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies local quality by allowing each hierarchical level to define its own authorization rules and group structures tailored to its specific needs. Each business unit or department can customize its authorization model locally without affecting the entire enterprise, making the system more intuitive and manageable at each level.

Inventive Principle:
Principle #3Local quality

3Stability of the object's composition

If global authorization definitions are defined in a central server, then consistent authorization across the organization is achieved, but adaptability deteriorates when domain expertise and specific application requirements are needed

Engineering Contradiction:
Improveauthorization consistencyVSAvoiddomain-specific adaptation
Core Design Contradiction:
Stability of the object's compositionVSAdaptability or versatility

Solution Approach 1:

The patent segments global authorization definitions into hierarchical layers: enterprise-level policies provide consistent baseline authorization, while business unit and department-level policies provide domain-specific adaptations. This segmentation allows both consistency and adaptability to coexist at different hierarchical levels.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent merges global and local authorization definitions into a unified hierarchical policy framework. Enterprise-level policies are combined with business unit-specific and department-specific policies to create comprehensive authorization rules that maintain consistency while accommodating domain expertise and specific application requirements.

Inventive Principle:
Principle #5Merging (Combining)

4Extent of automation

If automated role modeling based on existing permissions is implemented, then role generation is automated, but applicability deteriorates when new implementation lacks existing permissions or classification accuracy is insufficient

Engineering Contradiction:
Improverole modeling automationVSAvoidnew implementation applicability
Core Design Contradiction:
Extent of automationVSAdaptability or versatility

Solution Approach 1:

The patent applies preliminary action by pre-defining role templates and authorization patterns at the enterprise level before specific implementations. These pre-configured templates can be automatically instantiated for new business units or applications, enabling automated role modeling even when existing permissions are unavailable, as the system can generate roles based on predefined patterns rather than analyzing existing permissions.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP2711860B1System and method for managing role based access control of users
Publication Date: 2020.11.25 TATA CONSULTANCY SERVICES LTD
  • EP2711860B1 patent drawingFigure 1
  • EP2711860B1 patent drawingFigure 2
  • EP2711860B1 patent drawingFigure 3

AI summary

A method and system for role based access control for a plurality of users in a heterogeneous enterprise environment, comprising: establishing a functional relationship between a plurality of provisioning unit using a provision unit module. The users are mapped with the provisioning unit based on attributes of the users. Events are captured via the provision unit module. The users needed to be re-mapped are determined upon the event completion. Application role defined in context of an application embedded in an application registry module is mapped with the provisioning unit. Call back service is executed for the re-mapped users having entitlement associated with each of the application stored in a roles registry module. An application role is determined and defined for a new user for the plurality of the application enabling managing of the role based access control.