Role Generation via Metadata Comparison Across Platforms

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The proliferation of mobile applications and multiple platforms in corporate environments leads to increased administrative burdens and security risks due to the complexity of assigning and managing applications across various environments, with existing role structures lacking context and clarity.

Innovation Solution

A computer-implemented method that generates roles for a new platform by leveraging existing role metadata, comparing semantic attributes of first-platform roles with second-platform applications, and assigning relevant applications based on matches, facilitating automatic and meaningful role generation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If manual assignment of applications to roles is performed across multiple platforms, then role definitions can be customized for each platform, but administrative time and resources are consumed excessively

Engineering Contradiction:
Improverole customizationVSAvoidadministrative time
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The system automatically copies role definitions from a source platform to a target platform by extracting role metadata (name, description, assigned applications) from the source platform and replicating it on the target platform. This copying mechanism preserves role customization while eliminating manual re-creation efforts, directly resolving the contradiction between adaptability and time consumption.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The system performs preliminary extraction of role metadata from the source platform before the actual role creation on the target platform. By pre-processing and structuring the role information in advance, the system prepares everything needed for automatic role deployment, reducing the time required during the actual role assignment process while maintaining customization capabilities.

Inventive Principle:
Principle #10Preliminary action

2Ease of manufacture

If roles are defined without contextual metadata, then role creation is simpler, but the roles lack clarity about what can and should be encompassed

Engineering Contradiction:
Improverole creation simplicityVSAvoidrole context
Core Design Contradiction:
Ease of manufactureVSLoss of information

Solution Approach 1:

The system merges role metadata extraction with the role creation process by simultaneously capturing role name, description, and assigned applications from the source platform. This merging ensures that contextual information is preserved during replication without adding separate manual steps, maintaining both simplicity and information completeness.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The role metadata structure serves multiple functions: it defines the role identity (name), provides contextual description (description), and establishes application assignments (assigned applications). This universal metadata framework handles multiple information requirements in a single structured format, preventing information loss while keeping the creation process straightforward.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Adaptability or versatility

If multiple platforms are managed separately, then each platform can be optimized independently, but security risks increase due to managing many environments

Engineering Contradiction:
Improveplatform independenceVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system copies role definitions and application assignments from a source platform to a target platform, ensuring consistent security policies across multiple platforms. This replication mechanism maintains platform independence for optimization while enforcing uniform security standards, thereby reducing security risks associated with managing multiple environments separately.

Inventive Principle:
Principle #26Copying

4Productivity

If automatic role generation is implemented, then deployment speed increases, but the roles may lack meaningful context without proper metadata comparison

Engineering Contradiction:
Improvedeployment speedVSAvoidrole meaning
Core Design Contradiction:
ProductivityVSLoss of information

Solution Approach 1:

The system automatically copies role metadata including name, description, and assigned applications from the source platform to the target platform. This copying process enables rapid deployment while preserving the meaningful context of roles, as all essential information is replicated automatically without manual intervention or loss of semantic meaning.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The system replaces manual role creation and metadata assignment with an automated metadata extraction and replication mechanism. This substitution of mechanical manual processes with an automated system increases deployment speed while ensuring that role meaning is preserved through systematic copying of all relevant metadata fields.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS9262745B2Generating roles for a platform based on roles for an existing platform
Publication Date: 2016.02.16 SAP PORTALS ISRAEL
  • US9262745B2 patent drawing
  • US9262745B2 patent drawing
  • US9262745B2 patent drawing

AI summary

A computer-implemented method includes: receiving, using a computer system, first metadata portions regarding each of multiple first-platform roles defined for a first platform, each of the first-platform roles identifying at least one of multiple first-platform applications; generating, using the computer system, second-platform roles for a second platform, each of the second-platform roles corresponding to at least one of the first-platform roles; for each of the second-platform roles, accessing the first metadata portions for the corresponding at least one of the first-platform roles, and comparing, using the computer system, the accessed first metadata portions with second metadata portions assigned to multiple second-platform applications; and for each of the second-platform roles, assigning, using the computer system, at least one of the multiple second-platform applications to the second-platform role based on a match between at least one of the accessed first metadata portions and at least one of the second metadata portions.