Reference Architecture Pattern Permissions Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional role-based access and permission management systems become complex and inefficient in software-defined environments like cloud computing, particularly when handling sensitive data, due to the need for numerous customized roles and permissions across various stages of application development, deployment, and operation.

Innovation Solution

Implementing a reference architecture pattern-based permissions management system that defines roles and permissions using blueprints, cookbooks, and templates, allowing automatic assignment of permissions based on the reference architecture pattern, tier, and account, reducing complexity by focusing on negative permissions and dynamic rule-based access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional role-based access control is used in cloud computing environments, then security coverage is improved, but system complexity increases significantly

Engineering Contradiction:
Improvesecurity coverageVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies universality by creating a standardized role definition framework that can be reused across multiple cloud services and stages. Instead of defining custom roles for each service, the same set of standardized roles (e.g., developer, operator, administrator) are applied universally across development, test, and production environments, reducing the number of role definitions needed while maintaining comprehensive security coverage

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent segments permission management into distinct, manageable components: role definitions, service definitions, and stage definitions. Each component is independently configurable and can be combined through a matrix approach, allowing complex permission scenarios to be built from simple, reusable building blocks rather than managing monolithic role configurations

Inventive Principle:
Principle #1Segmentation

2Manufacturing precision

If customized roles are defined for each application stage and entity, then access control precision is improved, but time consumption increases

Engineering Contradiction:
Improveaccess control precisionVSAvoidtime consumption
Core Design Contradiction:
Manufacturing precisionVSLoss of time

Solution Approach 1:

The patent implements preliminary action by pre-defining a comprehensive set of standardized roles with specific permission profiles before deployment. These roles are designed in advance to cover common access scenarios across different stages and services, eliminating the need to create custom roles during implementation and reducing configuration time while maintaining precise access control

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses copying by allowing role definitions to be replicated and reused across multiple services and stages. A role defined for one service can be copied and applied to other services with minimal modification, and role assignments can be templated across development stages, significantly reducing the time required to configure access control for multiple applications

Inventive Principle:
Principle #26Copying

3Measurement precision

If traditional permission management is applied to each application independently, then security accuracy is improved, but operational efficiency decreases

Engineering Contradiction:
Improvesecurity accuracyVSAvoidoperational efficiency
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The patent applies universality by creating a centralized role management system that serves multiple applications and services simultaneously. The same role definitions and permission matrices are reused across different applications, maintaining security accuracy through consistent enforcement while dramatically improving operational efficiency by eliminating redundant permission management activities

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent merges permission management across multiple applications by implementing a unified role definition framework. Instead of managing permissions separately for each application, the system combines them into a single manageable structure where roles, services, and stages are defined once and applied collectively, reducing operational overhead while maintaining precise security control

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentEP3138263B1Method and system for providing reference architecture pattern-based permissions management
Publication Date: 2020.11.25 INTUIT INC
  • EP3138263B1 patent drawingFigure 1
  • EP3138263B1 patent drawingFigure 2
  • EP3138263B1 patent drawingFigure 3

AI summary

Reference architecture pattern role data representing reference architecture pattern roles to be associated with entities taking part in the development, and/or deployment, and/or operation of an application is generated. Reference architecture pattern tier data representing reference architecture pattern tiers used to create, and/or deploy, and/or operate an application using the reference architecture pattern is generated. For each reference architecture pattern role at least one access and/or operational permission is associated with each reference architecture pattern tier. At least one entity is assigned one of the reference architecture pattern roles and for each reference architecture pattern tier, the at least one entity is automatically provided the at least one access and/or operational permission associated with the reference architecture pattern role assigned to the entity.