Policy and Entitlement Framework for Granular Enterprise Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems fail to provide granular access control to enterprise applications, leading to users accessing all resources within a membership group once granted access, and manual updates are required for network changes like adding new firewalls, consuming time and resources.

Innovation Solution

A multi-purpose tool allows application owners to define policies and entitlements for membership groups, enabling fine-grained access control through automated discovery and enforcement of access permissions and block rules, and automatically updates firewall information for new network segments.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional physical isolation facilities are used to secure network communications, then security is improved, but device complexity and adaptability deteriorate

Engineering Contradiction:
ImprovesecurityVSAvoidphysical isolation facilities
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces traditional physical isolation facilities with a software-defined perimeter (SDP) system that uses cryptographic protocols and virtual network tunnels to achieve security isolation. This substitution eliminates the need for complex physical infrastructure while maintaining security functionality through software-based mechanisms.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent transforms the security isolation mechanism from physical parameters to cryptographic parameters. By using encryption keys, digital certificates, and cryptographic hash functions, the system achieves security isolation without physical barriers, thereby reducing device complexity while maintaining reliability.

Inventive Principle:
Principle #35Parameter changes

2Measurement precision

If granular access control policies are implemented, then access management precision is improved, but device complexity and ease of operation deteriorate

Engineering Contradiction:
Improveaccess control precisionVSAvoidpolicy management system
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments access control into discrete policy components including entitlements, permissions, and access control lists. Each component can be independently managed and configured, allowing granular control over specific resources while simplifying the overall policy management structure through modular design.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a policy management system as an intermediary between users and resources. This intermediary automatically evaluates access requests against defined policies and entitlements, reducing the operational burden on administrators while maintaining precise control over access permissions.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Measurement precision

If manual firewall configuration updates are performed, then access control precision is improved, but loss of time and productivity deteriorate

Engineering Contradiction:
Improveaccess control precisionVSAvoidfirewall update time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent performs preliminary action by automatically discovering new network resources and pre-configuring their access policies before they are needed. The system proactively updates firewall rules based on discovered resources, eliminating the need for manual intervention and reducing time loss.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements a feedback mechanism where the policy management system continuously monitors network changes and automatically adjusts firewall configurations. This closed-loop system receives feedback about new resources and autonomously updates access control policies, eliminating manual update processes and improving productivity.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS12615261B2Enterprise user access discovery and management using policy and entitlement framework
Publication Date: 2026.04.28 T MOBILE INNOVATIONS LLC
  • US12615261B2 patent drawing
  • US12615261B2 patent drawing
  • US12615261B2 patent drawing

AI summary

A system and method for enabling fine-grained access to enterprise applications in an enterprise network. The method includes receiving, via a discovery application running on a computing device, user input from a user, where the user input identifies at least one of an application name, a server name, or an Internet Protocol (IP) address associated with a computing resource for accessing an enterprise application; comparing, via the discovery application, the user input to application information stored in a database accessible by the discovery application; sending, via the discovery application, a message to the user in response to determining a match between the user input and the application information, where the message identifies a membership group containing the computing resource for accessing the enterprise application; and enabling the user to access the membership group using the computing resource when the user is a member of the membership group.