Role-Based Object Identifier Schema for Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Role-based access control systems face challenges in managing access permissions across different applications and organizations due to varying job titles and role names, leading to the need for customized security policies and increased administrative burden.
Innovation Solution
The implementation of a Role-Based Object Identifier (RBOID) schema that provides a globally unique identifier for roles, enabling a single security policy to be enforced across various applications, regardless of different role names, by associating roles with RBOIDs that define access permissions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If traditional role-based access control systems use pre-defined roles with customized security policies for each application, then access permissions can be managed for each specific application, but the administrative burden increases and consistency across applications deteriorates
Solution Approach 1:
The patent implements a universal role identifier schema (using OIDs) that can be applied across multiple applications and organizations. Instead of creating customized security policies for each application, the system uses a standardized role identification framework that works universally, eliminating the need for repetitive policy customization while maintaining appropriate access control across diverse applications.
Solution Approach 2:
The system changes the parameter of role identification from application-specific custom identifiers to standardized OIDs (Object Identifiers). This parameter change enables consistent role recognition across different applications without requiring customized security policies for each one, thereby reducing administrative complexity while maintaining adaptability.
2Ease of operation
If job titles are used to determine access permissions, then benefits and privileges can be assigned based on organizational hierarchy, but role names vary greatly across industries and companies leading to inconsistency
Solution Approach 1:
The patent applies a universal OID-based role identification schema that can represent various organizational roles (staff, manager, VP, CEO, etc.) across different industries and companies. This universal framework maintains the ability to assign benefits and privileges based on organizational hierarchy while ensuring consistent role identification regardless of varying job titles across different organizations.
Solution Approach 2:
The system introduces OIDs as an intermediary layer between diverse job titles and access permissions. Instead of directly mapping varying job titles to permissions, the OIDs serve as a standardized mediator that translates different organizational role names into consistent identification, thereby maintaining reliability while preserving the ease of assigning benefits based on organizational structure.
3Reliability
If customized security policies are created for each application, then specific access requirements can be met, but the need for customized policies increases administrative complexity
Solution Approach 1:
The patent implements a universal role identifier schema using OIDs that can be applied across multiple applications with different access requirements. Instead of creating customized security policies for each application, the standardized OID framework enables consistent role recognition and permission assignment across diverse applications, maintaining access control accuracy while eliminating the need for repetitive policy customization.
4Reliability
If multiple approvers are needed for different applications, then proper authorization can be ensured, but the approval process becomes more complex and time-consuming
Solution Approach 1:
The patent applies a universal role-based access control framework that can be consistently applied across multiple applications. By using standardized OIDs for role identification, the system enables a single approval process to validate roles that work across all applications, eliminating the need for separate approval processes for each application while maintaining proper authorization accuracy.
Data Source
AI summary
A method includes receiving a first user request to access or modify a first application, the first user request including a first object identifier (OID), the first OID identifying a first role of the first user. The method further includes determining whether the first OID is equivalent to a first application-specific role, and in response to determining that the first OID is equivalent to the first application-specific role, authorizing the first user request.


