Policy Engine for Consistent Access Authorization Across Data Environments

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Modern enterprises face challenges in ensuring consistent overarching business requirements across diverse data environments managed by different systems and platforms, leading to difficulties in enforcing access authorization policies effectively.

Innovation Solution

A rule and policy engine automates Identity Governance and Administration by mapping high-level business requirements into enforceable policies and rules across data environments, ensuring compliance and access control through a lifecycle of rule enforcement stages.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If different database systems and platforms are used by different departments to meet specific functional requirements, then the adaptability and versatility of data environments are improved, but the consistency and uniformity of access policy enforcement deteriorate

Engineering Contradiction:
Improvedata environment adaptabilityVSAvoidpolicy enforcement consistency
Core Design Contradiction:
Adaptability or versatilityVSStability of the object's composition

Solution Approach 1:

The patent introduces a centralized policy management system that acts as an intermediary between users and diverse data environments. This system translates high-level business requirements into platform-specific access rules, enabling uniform policy enforcement across heterogeneous databases and platforms without requiring changes to the underlying systems.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The policy management system is designed to work universally across multiple different database systems and platforms simultaneously. It provides a single unified interface for defining access policies that can be enforced across various data environments with different capabilities and requirements.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Ease of operation

If multiple identity management platforms are used to manage user identities across departments, then the ease of operation for specific departments is improved, but the reliability of overarching business requirement implementation deteriorates

Engineering Contradiction:
Improvedepartmental operation easeVSAvoidbusiness requirement implementation reliability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent merges the functions of multiple departmental identity management platforms into a centralized policy management system. This consolidation maintains the operational ease benefits of specialized platforms while ensuring reliable enforcement of overarching business requirements through unified policy control.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system implements feedback mechanisms that monitor and enforce policy compliance across all identity management platforms. It provides visibility and control over whether business requirements are being met, allowing for corrective action when deviations occur.

Inventive Principle:
Principle #23Feedback

3Productivity

If decentralized data environment management is allowed to meet diverse departmental needs, then the productivity and flexibility of individual departments are improved, but the difficulty of detecting and measuring policy compliance increases

Engineering Contradiction:
Improvedepartmental productivityVSAvoidpolicy compliance monitoring difficulty
Core Design Contradiction:
ProductivityVSDifficulty of detecting and measuring

Solution Approach 1:

The centralized policy management system establishes feedback loops that automatically monitor compliance with access policies across decentralized data environments. It detects and reports policy violations or deviations, making compliance measurement straightforward despite the distributed nature of the systems.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS20240406214A1Consistent rule-based policy enforcement for access authorization
Publication Date: 2024.12.05 SERVICENOW INC
  • US20240406214A1 patent drawing
  • US20240406214A1 patent drawing
  • US20240406214A1 patent drawing

AI summary

The technology disclosed herein enables control of permissions to access resources of data environments based on business requirements. In a particular example, a method provides determining a high-level requirement for access to data environments and defining an access policy that maps to the high-level requirement. The method further provides generating one or more rules to implement the access policy and enforcing the rules on access requests to the data environments to satisfy the high-level requirement.