Role-Based Object Identifier Schema for Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Role-based access control systems face challenges in managing access permissions across different applications and organizations due to varying job titles and role names, leading to the need for customized security policies and increased administrative burden.

Innovation Solution

The implementation of a Role-Based Object Identifier (RBOID) schema that provides a globally unique identifier for roles, enabling a single security policy to be enforced across various applications, regardless of different role names, by associating roles with RBOIDs that define access permissions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If traditional role-based access control systems use pre-defined roles with customized security policies for each application, then access permissions can be managed for each specific application, but the administrative burden increases and consistency across applications deteriorates

Engineering Contradiction:
Improveaccess permission managementVSAvoidadministrative burden
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements a universal role identifier schema (using OIDs) that can be applied across multiple applications and organizations. Instead of creating customized security policies for each application, the system uses a standardized role identification framework that works universally, eliminating the need for repetitive policy customization while maintaining appropriate access control across diverse applications.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system changes the parameter of role identification from application-specific custom identifiers to standardized OIDs (Object Identifiers). This parameter change enables consistent role recognition across different applications without requiring customized security policies for each one, thereby reducing administrative complexity while maintaining adaptability.

Inventive Principle:
Principle #35Parameter changes

2Ease of operation

If job titles are used to determine access permissions, then benefits and privileges can be assigned based on organizational hierarchy, but role names vary greatly across industries and companies leading to inconsistency

Engineering Contradiction:
Improvebenefits and privileges assignmentVSAvoidrole identification consistency
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent applies a universal OID-based role identification schema that can represent various organizational roles (staff, manager, VP, CEO, etc.) across different industries and companies. This universal framework maintains the ability to assign benefits and privileges based on organizational hierarchy while ensuring consistent role identification regardless of varying job titles across different organizations.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system introduces OIDs as an intermediary layer between diverse job titles and access permissions. Instead of directly mapping varying job titles to permissions, the OIDs serve as a standardized mediator that translates different organizational role names into consistent identification, thereby maintaining reliability while preserving the ease of assigning benefits based on organizational structure.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If customized security policies are created for each application, then specific access requirements can be met, but the need for customized policies increases administrative complexity

Engineering Contradiction:
Improveaccess control accuracyVSAvoidsecurity policy management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal role identifier schema using OIDs that can be applied across multiple applications with different access requirements. Instead of creating customized security policies for each application, the standardized OID framework enables consistent role recognition and permission assignment across diverse applications, maintaining access control accuracy while eliminating the need for repetitive policy customization.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Reliability

If multiple approvers are needed for different applications, then proper authorization can be ensured, but the approval process becomes more complex and time-consuming

Engineering Contradiction:
Improveauthorization accuracyVSAvoidapproval process time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies a universal role-based access control framework that can be consistently applied across multiple applications. By using standardized OIDs for role identification, the system enables a single approval process to validate roles that work across all applications, eliminating the need for separate approval processes for each application while maintaining proper authorization accuracy.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20250021674A1Role-based object identifier schema
Publication Date: 2025.01.16 WELLS FARGO BANK NA
  • US20250021674A1 patent drawing
  • US20250021674A1 patent drawing
  • US20250021674A1 patent drawing

AI summary

A method includes receiving a first user request to access or modify a first application, the first user request including a first object identifier (OID), the first OID identifying a first role of the first user. The method further includes determining whether the first OID is equivalent to a first application-specific role, and in response to determining that the first OID is equivalent to the first application-specific role, authorizing the first user request.