Reference Architecture Pattern Permissions Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional role-based access and permission control systems create complexity and inefficiency in cloud computing environments, making it difficult to manage access for sensitive data like financial data, as each stage of application development, deployment, and operation requires numerous customized roles and permissions, which is repetitive and inefficient.

Innovation Solution

A permissions management system based on reference architecture patterns, where roles and permissions are defined once and applied across multiple applications of the same pattern type, automatically assigning permissions based on the reference architecture pattern, tier, and account accessed.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If traditional role-based access control systems are used in cloud computing environments, then access control for each application can be customized, but system complexity and management overhead increase significantly

Engineering Contradiction:
Improveaccess control customizationVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements a universal permission management system where a single permission definition can be applied across multiple applications and services in the cloud environment. Instead of creating separate role-based access control configurations for each application, the system defines permissions once at a higher level and automatically applies them across the cloud infrastructure, reducing system complexity while maintaining adaptability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Manufacturing precision

If customized roles and permissions are defined for each application stage, then access control precision is improved, but time and effort required for permission management increases

Engineering Contradiction:
Improveaccess control precisionVSAvoidpermission management time
Core Design Contradiction:
Manufacturing precisionVSLoss of time

Solution Approach 1:

The patent establishes permission definitions and access control policies in advance at the cloud infrastructure level, before applications are deployed. By pre-configuring the permission framework and automatically applying it to applications during deployment, the system maintains precise access control without requiring manual configuration for each application stage, thereby reducing the time and effort required for permission management.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If traditional permission management is applied to each application individually, then security control is maintained, but productivity and efficiency decrease

Engineering Contradiction:
Improvesecurity controlVSAvoidpermission management efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent merges permission management across multiple applications and services into a unified cloud-level system. By combining individual application permission controls into a centralized framework that operates at the cloud infrastructure level, the system maintains security control while significantly improving productivity and efficiency in permission management.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS9900322B2Method and system for providing permissions management
Publication Date: 2018.02.20 INTUIT INC
  • US9900322B2 patent drawing
  • US9900322B2 patent drawing
  • US9900322B2 patent drawing

AI summary

Reference architecture pattern role data representing reference architecture pattern roles to be associated with entities taking part in the development, and/or deployment, and/or operation of an application is generated. Reference architecture pattern tier data representing reference architecture pattern tiers used to create, and/or deploy, and/or operate an application using the reference architecture pattern is generated. For each reference architecture pattern role at least one access and/or operational permission is associated with each reference architecture pattern tier. An entity is assigned one of the reference architecture pattern roles and for each reference architecture pattern tier, the entity is automatically provided the at least one access and/or operational permission associated with the reference architecture pattern role assigned to the entity. When a computing task is requested, permissions associated with the computing task are adjusted based on a risk level associated with performance of the requested computing task.