Role Mapping for Federated Portal Entitlement Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current Web Services for Remote Portlets (WSRP) lack effective mechanisms for controlling access to portlets across different consumer applications, leading to challenges in dynamically integrating business applications and managing user entitlements within federated portals.

Innovation Solution

A system and method that allows Producer web applications to manage consumer entitlements by defining roles and mapping consumer web applications to specific roles based on registration properties, enabling finer-grained control over which portlets are offered to consumers, thereby controlling access and usage rights.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If WSRP is used to dynamically integrate portlets across consumer applications, then adaptability and ease of operation are improved, but access control and security management become more complex

Engineering Contradiction:
Improvedynamic integration capabilityVSAvoidaccess control complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments access control into distinct roles (producer roles and consumer roles) that can be independently defined and assigned. This allows the system to manage complex access control requirements by breaking them down into manageable role-based units, where each role encapsulates specific entitlements to specific portlets.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary mechanism (the role mapping system) that sits between the consumer applications and the portlet resources. This intermediary automatically manages access control by mapping consumer roles to producer roles, eliminating the need for complex direct access control logic in each consumer application.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If role-based access control is implemented to manage consumer entitlements, then security is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates a universal role mapping mechanism that handles multiple security scenarios through a single framework. The same role mapping infrastructure manages both producer-to-portlet entitlements and consumer-to-portlet entitlements, reducing overall system complexity despite the enhanced security capabilities.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system implements self-service automation where the role mapping mechanism automatically determines entitlements based on predefined role configurations. This eliminates the need for manual access control management and reduces operational complexity, as the system autonomously enforces security policies.

Inventive Principle:
Principle #25Self-service

3Reliability

If fine-grained control over portlet access is implemented, then security and entitlement management are improved, but ease of operation decreases

Engineering Contradiction:
Improveentitlement managementVSAvoidconfiguration simplicity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent uses role templates that can be copied and reused across different consumer applications. Once a role mapping is defined for a particular scenario, it can be replicated and adapted for similar scenarios, significantly reducing configuration effort and maintaining fine-grained control without increasing operational complexity.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS8838734B2System and method for supporting consumer entitlements in federate portal
Publication Date: 2014.09.16 ORACLE INT CORP
  • US8838734B2 patent drawing
  • US8838734B2 patent drawing
  • US8838734B2 patent drawing

AI summary

A system and method can support a federated portal using a producer web application on a web server and a plurality of consumer web applications. The producer web application is a container web application that hosts a plurality of portlet applications that are deployed and maintained separately. Each consumer web application is adapted to collect and present available portlet applications hosted on the producer web application and offer them as a unified portal to end users. Upon receiving a request from a consumer web application, said producer web application can map the consumer web application to one particular role in a role set which includes a plurality of roles, check for portlet applications that are available based on the particular role, and response to the consumer web application with a message that describes the available portlet applications hosted in the producer web application.