Role Mapping for Federated Portal Entitlement Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current Web Services for Remote Portlets (WSRP) lack effective mechanisms for controlling access to portlets across different consumer applications, leading to challenges in dynamically integrating business applications and managing user entitlements within federated portals.
Innovation Solution
A system and method that allows Producer web applications to manage consumer entitlements by defining roles and mapping consumer web applications to specific roles based on registration properties, enabling finer-grained control over which portlets are offered to consumers, thereby controlling access and usage rights.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If WSRP is used to dynamically integrate portlets across consumer applications, then adaptability and ease of operation are improved, but access control and security management become more complex
Solution Approach 1:
The patent segments access control into distinct roles (producer roles and consumer roles) that can be independently defined and assigned. This allows the system to manage complex access control requirements by breaking them down into manageable role-based units, where each role encapsulates specific entitlements to specific portlets.
Solution Approach 2:
The patent introduces an intermediary mechanism (the role mapping system) that sits between the consumer applications and the portlet resources. This intermediary automatically manages access control by mapping consumer roles to producer roles, eliminating the need for complex direct access control logic in each consumer application.
2Reliability
If role-based access control is implemented to manage consumer entitlements, then security is improved, but device complexity increases
Solution Approach 1:
The patent creates a universal role mapping mechanism that handles multiple security scenarios through a single framework. The same role mapping infrastructure manages both producer-to-portlet entitlements and consumer-to-portlet entitlements, reducing overall system complexity despite the enhanced security capabilities.
Solution Approach 2:
The system implements self-service automation where the role mapping mechanism automatically determines entitlements based on predefined role configurations. This eliminates the need for manual access control management and reduces operational complexity, as the system autonomously enforces security policies.
3Reliability
If fine-grained control over portlet access is implemented, then security and entitlement management are improved, but ease of operation decreases
Solution Approach 1:
The patent uses role templates that can be copied and reused across different consumer applications. Once a role mapping is defined for a particular scenario, it can be replicated and adapted for similar scenarios, significantly reducing configuration effort and maintaining fine-grained control without increasing operational complexity.
Data Source
AI summary
A system and method can support a federated portal using a producer web application on a web server and a plurality of consumer web applications. The producer web application is a container web application that hosts a plurality of portlet applications that are deployed and maintained separately. Each consumer web application is adapted to collect and present available portlet applications hosted on the producer web application and offer them as a unified portal to end users. Upon receiving a request from a consumer web application, said producer web application can map the consumer web application to one particular role in a role set which includes a plurality of roles, check for portlet applications that are available based on the particular role, and response to the consumer web application with a message that describes the available portlet applications hosted in the producer web application.


