Enterprise Search Security via Attribute Parameterization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing search systems face challenges in securely accessing and indexing content across enterprise applications with dynamic security hierarchies, as they lack the ability to handle varying security attributes and user role mappings, leading to complications in authentication and authorization processes.

Innovation Solution

A flexible and extensible architecture that enables secure enterprise search by authenticating users through a flexible framework, submitting security attributes at query time, and using APIs to authorize access across disparate systems, allowing for real-time secure access and dynamic querying.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of information

If traditional crawling methods are used to index content across enterprise applications, then search coverage can be achieved, but security authentication and authorization become highly complex and difficult to manage

Engineering Contradiction:
Improvesearch coverageVSAvoidauthentication and authorization complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary component that sits between the search system and enterprise applications, handling security authentication and authorization. This intermediary translates security requirements into a standardized format, allowing the search system to access multiple enterprise applications without directly implementing complex security logic for each application, thus reducing overall system complexity while maintaining comprehensive search coverage.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If security attributes are checked for each user query across multiple enterprise applications, then secure access control is ensured, but query performance and response time deteriorate

Engineering Contradiction:
Improvesecure access controlVSAvoidquery performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements preliminary action by pre-computing and caching security attributes for users during login or idle periods. Security clearance information is stored in a cache mechanism, allowing subsequent queries to bypass repeated authentication checks. This preliminary preparation ensures secure access control is maintained while significantly improving query performance, as the system can quickly retrieve cached security information rather than re-evaluating permissions for each query.

Inventive Principle:
Principle #10Preliminary action

3Stability of the object's composition

If a rigid security model is implemented across all enterprise applications, then consistent security policy enforcement is achieved, but adaptability to different application-specific security requirements is lost

Engineering Contradiction:
Improvesecurity policy consistencyVSAvoidapplication-specific security adaptability
Core Design Contradiction:
Stability of the object's compositionVSAdaptability or versatility

Solution Approach 1:

The patent applies local quality by allowing different enterprise applications to define their own security attribute schemas and requirements while maintaining a consistent overall security framework. Each application can specify its unique security needs (e.g., role-based, attribute-based), and the intermediary translates these local requirements into the standardized security model. This approach ensures both consistent security policy enforcement across the enterprise and adaptability to application-specific requirements.

Inventive Principle:
Principle #3Local quality

4Productivity

If security credentials are stored long-term for authenticated users, then authentication efficiency is improved, but security risk from credential exposure increases

Engineering Contradiction:
Improveauthentication efficiencyVSAvoidsecurity risk from credential exposure
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent implements disposable short-lived security credentials that are generated temporarily for each search session or query batch. Instead of storing long-term credentials, the system creates ephemeral authentication tokens that expire after use or after a short time period. This approach maintains authentication efficiency by having valid credentials ready for each session while minimizing security risk, as the short lifespan and limited reuse of credentials reduce the window for potential exploitation.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Data Source

PatentUS8352475B2Suggested content with attribute parameterization
Publication Date: 2013.01.08 ORACLE INT CORP
  • US8352475B2 patent drawing
  • US8352475B2 patent drawing
  • US8352475B2 patent drawing

AI summary

A flexible and extensible architecture allows for secure searching across an enterprise. Such an architecture can provide a simple Internet-like search experience to users searching secure content inside (and outside) the enterprise. The architecture allows for the crawling and searching of a variety of sources across an enterprise, regardless of whether any of these sources conform to a conventional user role model. The architecture further allows for security attributes to be submitted at query time, for example, in order to provide real-time secure access to enterprise resources. The user query also can be transformed to provide for dynamic querying that provides for a more current result list than can be obtained for static queries.