Hierarchical Role-Based Access Control for Enterprise Systems
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing role-based access control (RBAC) systems face challenges in managing access entitlements across multiple business domains in large enterprises, particularly in complex operational environments, and fail to preserve the enterprise perspective, leading to inefficiencies and inaccuracies in authorization and resource management.
Innovation Solution
A system and method that utilizes a provisioning unit to manage role-based access control by viewing authorization rights as a mosaic, associating users with provisioning units based on attributes, and mapping application roles within an application registry module, allowing for the integration of access control across heterogeneous environments and preserving enterprise goals.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a central role server or LDAP directory structure is used to manage entitlements, then centralized control and retrieval of user permissions is achieved, but operational complexity increases and scalability deteriorates in large enterprises with complex operation patterns
Solution Approach 1:
The patent segments the centralized role server into multiple distributed role servers organized in a hierarchical structure. Each role server manages entitlements for a specific organizational unit or business domain, eliminating the single-point complexity of a central server while maintaining centralized control through hierarchical coordination.
Solution Approach 2:
The patent introduces a hierarchical dimension to the role server architecture, organizing role servers across multiple levels (enterprise-level, business unit-level, department-level). This dimensional transformation allows centralized control to be distributed across hierarchical layers, reducing operational complexity at any single level while maintaining enterprise-wide consistency.
2Ease of operation
If resource consumption groups are used for authorization, then group-based rights management is simplified, but intuitiveness deteriorates when numbers of groups grow beyond certain size and enterprise organizational perspective is lost
Solution Approach 1:
The patent segments the flat group structure into hierarchical organizational units that mirror the enterprise structure. Instead of creating numerous flat groups, the system creates hierarchical units (enterprise → business units → departments → teams) that naturally organize users and resources, reducing the perceived complexity as the organization grows.
Solution Approach 2:
The patent applies local quality by allowing each hierarchical level to define its own authorization rules and group structures tailored to its specific needs. Each business unit or department can customize its authorization model locally without affecting the entire enterprise, making the system more intuitive and manageable at each level.
3Stability of the object's composition
If global authorization definitions are defined in a central server, then consistent authorization across the organization is achieved, but adaptability deteriorates when domain expertise and specific application requirements are needed
Solution Approach 1:
The patent segments global authorization definitions into hierarchical layers: enterprise-level policies provide consistent baseline authorization, while business unit and department-level policies provide domain-specific adaptations. This segmentation allows both consistency and adaptability to coexist at different hierarchical levels.
Solution Approach 2:
The patent merges global and local authorization definitions into a unified hierarchical policy framework. Enterprise-level policies are combined with business unit-specific and department-specific policies to create comprehensive authorization rules that maintain consistency while accommodating domain expertise and specific application requirements.
4Extent of automation
If automated role modeling based on existing permissions is implemented, then role generation is automated, but applicability deteriorates when new implementation lacks existing permissions or classification accuracy is insufficient
Solution Approach 1:
The patent applies preliminary action by pre-defining role templates and authorization patterns at the enterprise level before specific implementations. These pre-configured templates can be automatically instantiated for new business units or applications, enabling automated role modeling even when existing permissions are unavailable, as the system can generate roles based on predefined patterns rather than analyzing existing permissions.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A method and system for role based access control for a plurality of users in a heterogeneous enterprise environment, comprising: establishing a functional relationship between a plurality of provisioning unit using a provision unit module. The users are mapped with the provisioning unit based on attributes of the users. Events are captured via the provision unit module. The users needed to be re-mapped are determined upon the event completion. Application role defined in context of an application embedded in an application registry module is mapped with the provisioning unit. Call back service is executed for the re-mapped users having entitlement associated with each of the application stored in a roles registry module. An application role is determined and defined for a new user for the plurality of the application enabling managing of the role based access control.