Nested Group Policy Inheritance for Enterprise Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing enterprise security systems face challenges in ensuring compatibility and scalability across heterogeneous computing environments, leading to incompatible security silos and high maintenance costs due to proprietary security models and the need for extensive training.

Innovation Solution

A distributed security system that enables fine-grained, business transaction-based authorization through flexible policies, allowing for simple integration with third-party security products and dynamic role management, with security provider modules applying policies to resources and using authentication, authorization, and auditing services.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If proprietary security models are implemented in each software application, then each application can have its own customized security policies, but security compatibility across different applications is lost and security silos are created

Engineering Contradiction:
Improvecustomized security policiesVSAvoidsecurity compatibility
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements a universal security framework that allows different security models to operate within a common architecture. The security framework provides standardized interfaces and policies that work across heterogeneous applications, enabling security compatibility while preserving the ability to implement customized security models for different applications.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Ease of operation

If extensive training is provided to software developers for security implementation, then security implementation capability is improved, but development time and cost increase

Engineering Contradiction:
Improvesecurity implementation capabilityVSAvoiddevelopment time
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The security framework enables developers to implement security without extensive training by providing self-service capabilities through standardized APIs, pre-configured security policies, and automatic security management. The system handles security configuration and enforcement automatically, reducing the need for specialized security knowledge while maintaining high security standards.

Inventive Principle:
Principle #25Self-service

3Reliability

If security measures are intricately tied to legacy applications, then application security is strengthened, but system flexibility and scalability are reduced

Engineering Contradiction:
Improveapplication securityVSAvoidsystem flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments security functionality into separate, modular components that can be independently configured and applied to different applications. The security framework separates security policies, authentication mechanisms, and authorization rules from the application logic, allowing security measures to be applied to legacy applications without modifying their core functionality while maintaining flexibility for future adaptations.

Inventive Principle:
Principle #1Segmentation

4Reliability

If multiple proprietary security models are deployed across enterprise services, then each service can have optimized security, but overall system maintenance cost and complexity increase

Engineering Contradiction:
Improveservice security optimizationVSAvoidmaintenance complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges multiple proprietary security models into a unified security framework that manages diverse security requirements through a single system. The framework consolidates security administration, policy management, and enforcement mechanisms, allowing optimized security for different services to be achieved while reducing maintenance complexity through centralized management and standardized interfaces.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS7644432B2Policy inheritance through nested groups
Publication Date: 2010.01.05 ORACLE INT CORP
  • US7644432B2 patent drawing
  • US7644432B2 patent drawing
  • US7644432B2 patent drawing

AI summary

A computer-implemented system and method for policy inheritance, comprising, defining a first group wherein the first group refers to at least one of: a user and a group different from the first group, defining a second group wherein the second group is nested within the first group, defining a first policy wherein the first policy includes a resource, a subject and one of, an action and a role, and wherein the subject includes the first group, inheriting the first policy by the second group, wherein the resource is part of a resource hierarchy, and wherein the first policy can be used to control access to the resource.