Pluggable Security Framework for Enterprise Search Integration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current enterprise search systems lack integration with business processes, visibility into search engine processes, control over search algorithms, scalability, and security, leading to suboptimal search experiences in complex business environments.

Innovation Solution

An enterprise crawl and search framework that abstracts search engines, provides a common API for search functionalities, includes pluggable security, and supports various search engines, allowing for integration with enterprise applications, scalable architecture, and secure search operations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If traditional search systems are used in enterprise environments, then basic search functionality is provided, but integration with business processes and security control are insufficient

Engineering Contradiction:
Improveintegration with business processesVSAvoidsecurity control
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces a security service as an intermediary component between the search engine and enterprise applications. This security service acts as a mediator that handles authentication, authorization, and security policy enforcement, allowing the search system to integrate with enterprise business processes while maintaining robust security control through a dedicated security layer

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If search engines are directly integrated with enterprise applications, then search functionality is available, but visibility into search processes and control over algorithms are lost

Engineering Contradiction:
Improvesearch functionalityVSAvoidcontrol over search algorithms
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent segments the search system into distinct functional components: the search engine itself, the security service, the crawl service, and the enterprise application layer. This segmentation allows each component to operate independently with well-defined interfaces, maintaining ease of operation while enabling control over search algorithms through the structured architecture that exposes algorithm parameters and configuration options

Inventive Principle:
Principle #1Segmentation

3Productivity

If enterprise applications access search engine directly, then search operations are performed, but security management and authorization are insufficient

Engineering Contradiction:
Improvesearch operationsVSAvoidsecurity management
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The security service serves as an intermediary that all enterprise applications must pass through when accessing the search engine. This intermediary handles authentication verification, authorization checks, and security policy enforcement, enabling efficient search operations while maintaining reliable security management through centralized security control

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The security service implements feedback mechanisms by continuously verifying user credentials, checking authorization levels, and enforcing security policies during search operations. This feedback loop ensures that security management remains robust while allowing productive search operations to proceed when security requirements are met

Inventive Principle:
Principle #23Feedback

4Adaptability or versatility

If multiple search engines are supported, then versatility is improved, but system complexity increases

Engineering Contradiction:
Improvesearch engine compatibilityVSAvoidsystem architecture
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements a universal security service and crawl service architecture that can work with multiple different search engines. These services provide multi-functional capabilities that adapt to different search engine types and configurations, improving versatility while managing system complexity through standardized interfaces and configuration-based adaptation

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9524308B2System and method for providing pluggable security in an enterprise crawl and search framework environment
Publication Date: 2016.12.20 ORACLE INT CORP
  • US9524308B2 patent drawing
  • US9524308B2 patent drawing
  • US9524308B2 patent drawing

AI summary

A system and method are described, wherein the system includes an enterprise crawl and search framework, abstracts an underlying search engine, provides a common set of application programming interfaces for developing search functionalities, and allows the framework to serve as an integration layer between one or more enterprise search engines and one or more enterprise applications. A pluggable security environment which includes one or more enterprise application security APIs, authentication services, security plugin, authorization service, and data service, allows an application developer to add security information to enterprise application data before inserting or creating indexes on the search engine, and deploy the enterprise application and use any policies in its configuration to configure enterprise application domain security, so that at query time, the security environment retrieves security keys of a user performing an enterprise application search, and passes those keys to the search engine for filtering the query results.