Role-Based Access Control via Protection Classes

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing role-based access control (RBAC) systems in content management systems require manual assignment of access privileges to resources, making them cumbersome and impractical for large and dynamic systems, as resources are added.

Innovation Solution

Implementing a method that automatically assigns permissions to resources by utilizing protection classes, where roles are dynamically determined based on predefined privilege sets and protection classes, allowing resources to inherit permissions and access control policies without explicit relationships.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Manufacturing precision

If manual assignment of access privileges is used when resources are added, then access control precision is maintained, but system complexity and administrative burden increase significantly

Engineering Contradiction:
Improveaccess control precisionVSAvoidsystem complexity
Core Design Contradiction:
Manufacturing precisionVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by pre-defining protection classes and their associated permission sets before resources are added to the system. When a resource is created, it is automatically assigned to an appropriate protection class, which pre-determines the access privileges. This eliminates the need for manual permission assignment at resource creation time, reducing administrative burden while maintaining precise access control through the predefined protection class structures.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If manual assignment of access privileges is used, then role-based access control is implemented, but scalability and ease of operation deteriorate in large dynamic systems

Engineering Contradiction:
Improverole-based access controlVSAvoidscalability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements universality by creating protection classes that serve as universal templates applicable to multiple resources with similar access requirements. Instead of configuring permissions individually for each resource, a single protection class definition can be applied across numerous resources, enabling the system to scale efficiently. When new resources are added, they inherit permissions from their protection class, maintaining role-based access control reliability while dramatically improving scalability and ease of operation.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Manufacturing precision

If manual permission assignment is required for each resource, then precise access control is achieved, but time consumption and productivity decrease

Engineering Contradiction:
Improveaccess control precisionVSAvoidsystem efficiency
Core Design Contradiction:
Manufacturing precisionVSProductivity

Solution Approach 1:

The patent applies merging by combining multiple permission assignments into a single protection class definition. Instead of manually configuring permissions for each resource individually, the system merges common permission patterns into reusable protection classes. When resources share the same protection class, their access control configurations are effectively merged, maintaining precise access control while dramatically reducing the time and effort required to manage permissions across the system.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS9455990B2System and method for role based access control in a content management system
Publication Date: 2016.09.27 SAILPOINT TECHNOLOGIES HOLDINGS INC
  • US9455990B2 patent drawing
  • US9455990B2 patent drawing
  • US9455990B2 patent drawing

AI summary

Embodiments of the present invention provide an efficient and scalable scheme for role-based access control to resources. The resources are assigned a protection class. Resources in the same protection class share the same access control policy. Permissions granted to various roles are then defined based on privilege sets and protection classes. Accordingly, the permissions of a role can be dynamically determined at runtime. Furthermore, as new resources are added, they can be assigned to a pre-existing protection class. The new resource may thus automatically inherit the various permissions and roles attached to the protection class.