Scope-Based Access Control for Device Group Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional systems management consoles struggle with efficiently managing large and diverse computing environments, often requiring unwieldy distribution of software updates and lacking organization of computing devices into groups, which complicates operations across diverse locations and intended functions.

Innovation Solution

A scope-based access control system utilizing an external global authentication authority, such as an OIDC-based server, to manage role-based access by grouping computing devices, enabling efficient operation and software updates based on user roles and device groups.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If conventional systems management consoles are used to manage large and diverse computing environments, then comprehensive management coverage is achieved, but the system becomes unwieldy and difficult to operate efficiently

Engineering Contradiction:
Improveease of managementVSAvoidsystem complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent segments the computing environment into hierarchical groups (e.g., organizational units, locations, device types) and allows users to manage devices at appropriate granularities. This segmentation transforms the unwieldy comprehensive management into manageable segmented operations, resolving the contradiction between comprehensive coverage and ease of operation.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces scope-based access control claims as an intermediary mechanism between users and computing devices. These claims act as mediators that automatically enforce organizational policies and group memberships, reducing the operational burden on users while maintaining comprehensive management control.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If software updates are distributed to all computing devices in a large environment, then comprehensive update coverage is achieved, but the distribution process becomes inefficient and time-consuming

Engineering Contradiction:
Improveupdate distribution efficiencyVSAvoidupdate distribution time
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The patent enables segmentation of device update operations by organizational scope, location, or device group. Administrators can distribute updates to specific scopes rather than all devices universally, significantly improving distribution efficiency and reducing time loss while maintaining comprehensive update capability when needed.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements partial action by allowing selective update distribution to specific device groups or scopes rather than forcing universal distribution. This enables administrators to apply updates only where necessary, improving productivity while reducing time consumption.

Inventive Principle:
Principle #16Partial or excessive action

3Ease of operation

If computing devices are not organized into groups, then simple device structure is maintained, but operations across diverse locations and functions become complicated

Engineering Contradiction:
Improveoperation efficiencyVSAvoiddevice organization structure
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent implements segmentation by organizing devices into hierarchical groups based on organizational units, locations, and functions. This segmentation enables efficient operations within each scope while maintaining overall system coherence, resolving the contradiction between operational efficiency and structural complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates universal group structures that can serve multiple purposes simultaneously (organizational hierarchy, location grouping, functional classification). This multi-functionality allows the same grouping mechanism to address diverse operational needs without proportionally increasing complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12169537B2Scope-based access control system and method
Publication Date: 2024.12.17 DELL PROD LP
  • US12169537B2 patent drawing
  • US12169537B2 patent drawing
  • US12169537B2 patent drawing

AI summary

A scope-based access control system includes a systems manager that is executed to receive a request to perform an operation on one of multiple computing devices in which the request includes a session identifier associated with an established session of a user who issued the request. The systems manager forwards the request and the session identifier to a global authentication authority. The global authentication authority responds to the request by issuing a claim that specifies a computing device group that the session is authorized to access. The systems manager receives the claim specifying a computing device group from the global authentication authority. The systems manager then performs the operation based on whether the one computing device is included in the computing device group.