Identity Management Platform Role-Based Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing identity management systems fail to effectively control user access rights across multiple applications without requiring updates to each individual application, leading to complex and resource-intensive management as user roles and entitlements vary within and across applications.

Innovation Solution

An identity management platform that manages user access across various applications by hiding or deactivating unauthorized functions, replacing them with authorized ones, and automatically logging users into relevant applications based on predefined roles and credentials, thereby simplifying access control and entitlement management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If centralized identity management is implemented, then access control efficiency is improved, but system complexity increases

Engineering Contradiction:
Improveaccess control efficiencyVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent introduces an identity management server as an intermediary component that sits between users and multiple applications. This server handles authentication and authorization decisions centrally, allowing applications to remain simple while gaining sophisticated access control. The intermediary absorbs the complexity of managing multiple application-specific access policies, resolving the contradiction by centralizing management functionality.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The identity management server provides universal access control services across multiple different applications through a single unified system. Instead of requiring separate access control mechanisms for each application, the server uses a common authentication framework and role-based access control model that works across all applications, improving efficiency while managing complexity through standardization.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Measurement precision

If role-based access control is implemented, then authorization precision is improved, but management complexity increases

Engineering Contradiction:
Improveauthorization precisionVSAvoidmanagement complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments access control into discrete roles with specific permission sets. Instead of managing individual user-access-application triplets, the system divides permissions into reusable role templates (e.g., administrator, analyst, viewer) that can be assigned to users. This segmentation improves authorization precision by clearly defining what each role can access while simplifying management through role inheritance and composition.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Access control policies and role definitions are pre-configured in the identity management server before users need access to applications. Role-based permission sets are established in advance, allowing users to be quickly assigned roles rather than having access rights configured individually. This preliminary action reduces management complexity by preparing access control structures beforehand.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If application-specific access control is implemented, then access security is improved, but operational efficiency deteriorates

Engineering Contradiction:
Improveaccess securityVSAvoidoperational efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent merges access control functionality from multiple application-specific systems into a single centralized identity management server. Instead of each application maintaining its own access control logic, the server consolidates authentication and authorization functions. This merging maintains security through unified policy enforcement while dramatically improving operational efficiency by eliminating redundant access control operations across applications.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS9330280B2Identity management, authorization and entitlement framework
Publication Date: 2016.05.03 WORKDAY INC
  • US9330280B2 patent drawing
  • US9330280B2 patent drawing
  • US9330280B2 patent drawing

AI summary

A system and method are provided for identity management of applications on computing devices. A set of applications is registered at an identity management system. Each application allows a different level of access permission to the application based on a user role associated with a user accessing the application. A set of user profiles associated with users are received. Each user profile includes a login credential for allowing access to the applications and a user role for defining a user level of access permission to the applications. An access request to access an application is received at the identity management system and responsive to the access request, a user associated with the access request is authenticated. Upon successful authentication, the user role associated with the authenticated user is determined and the user is allowed to access functions of the application corresponding to the determined user role.