Role Discovery via Privilege Cluster Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Legacy techniques for managing permissions in human resource management systems are unwieldy due to the increasing complexity of organizational structures and the rapid adoption of enterprise software, leading to inefficient authorization processes and a lack of effective role discovery or privilege cluster optimization.

Innovation Solution

The method involves analyzing permission clusters to discover optimal roles by accessing hierarchical organization charts, flattening them to enumerate inherited permissions, and optimizing these sets to minimize the number of roles while maximizing coverage, thereby facilitating efficient permission assignment.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If legacy techniques are used to grant authorizations based on job title, then authorization processes are simple, but the system becomes unwieldy as organizational complexity increases

Engineering Contradiction:
Improveauthorization process simplicityVSAvoidorganizational structure complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent introduces role mining as an intermediary process that automatically discovers and defines roles based on permission cluster analysis. This intermediary layer translates complex organizational structures and permission relationships into manageable role definitions, eliminating the need for manual role creation while maintaining simplicity in the authorization process.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs self-service by automatically mining roles from existing permission assignments and organizational data. The role mining process autonomously analyzes permission clusters, identifies patterns, and generates role definitions without requiring manual intervention from administrators, thereby handling organizational complexity automatically.

Inventive Principle:
Principle #25Self-service

2Adaptability or versatility

If more permissions are assigned to handle cross-functional responsibilities, then employee versatility increases, but permission management complexity increases

Engineering Contradiction:
Improveemployee versatilityVSAvoidpermission management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent merges multiple individual permissions into consolidated role definitions through role mining. By analyzing permission clusters and identifying patterns across different jobs and duties, the system combines related permissions into unified roles that can be assigned to employees with cross-functional responsibilities, thereby reducing permission management complexity while maintaining versatility.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The discovered roles serve as universal containers that can be assigned to multiple jobs and duties. A single role definition can cover permissions needed for cross-functional responsibilities, allowing employees to perform multiple functions without requiring separate permission assignments for each duty, thus reducing management complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Ease of manufacture

If traditional role-based authorization is used, then implementation is straightforward, but role discovery and optimization are lacking

Engineering Contradiction:
Improveimplementation easeVSAvoidrole discovery automation
Core Design Contradiction:
Ease of manufactureVSExtent of automation

Solution Approach 1:

The patent performs preliminary action by automatically discovering and optimizing roles before they are formally implemented. The role mining process analyzes existing permission assignments and organizational structures in advance, identifying optimal role definitions that can be subsequently implemented. This preliminary automated discovery maintains implementation ease while introducing automation to role creation.

Inventive Principle:
Principle #10Preliminary action

4Reliability

If permission clusters are not optimized, then all permissions are available for assignment, but the number of roles and role memberships becomes excessive

Engineering Contradiction:
Improvepermission coverageVSAvoidnumber of roles
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts essential permission patterns from the complete set of permissions through cluster analysis. By identifying and extracting commonly co-occurring permission combinations, the system creates condensed role definitions that cover necessary permissions while eliminating redundant or unnecessary role memberships, thereby reducing the number of roles while maintaining comprehensive permission coverage.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS9679264B2Role discovery using privilege cluster analysis
Publication Date: 2017.06.13 ORACLE INT CORP
  • US9679264B2 patent drawing
  • US9679264B2 patent drawing
  • US9679264B2 patent drawing

AI summary

Systems and methods used in human resource management systems. The method optimizes the assignment of permissions (e.g., ability to write to a database, ability to create a new account, etc.) to jobs. The method discovers relationships between jobs, duties and privileges by accessing an organization chart that relates a plurality of jobs, a plurality of specific duties to be performed within the purview of a given job, and a plurality of permissions for the respective duties of the job. The method then flattens the organization chart to enumerate the permissions inherited by the jobs. The method proceeds to mine the inherited permissions across the jobs to optimize the sets of permissions. The sets can be optimized (e.g., minimize number of sets, maximize coverage, etc.) and named so as to be conveniently assigned (e.g., by an HR person) to a job (e.g., in the case of a new employee).