Security Metadata Service for Enterprise Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current secure information systems face challenges in efficiently authenticating and authorizing users across diverse enterprise applications, leading to potential unauthorized access and complex management of user roles and permissions.

Innovation Solution

A system that utilizes a security metadata service and middleware to integrate authentication and authorization processes, enabling applications to request and manage authentication and authorization metadata through a common interface, decoupling these processes from specific applications and allowing for dynamic role assignment and attribute-based access control.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional authentication and authorization methods are used for each application, then application security can be maintained, but system complexity and management difficulty increase significantly

Engineering Contradiction:
Improveapplication securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a security metadata service as an intermediary component that sits between applications and the authentication/authorization infrastructure. This service provides a common interface for applications to request security metadata, decoupling them from direct integration with complex authentication systems. The security metadata service translates application security requirements into standardized metadata requests, managing the complexity centrally rather than at each application level.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates a universal security metadata service that handles authentication and authorization for multiple diverse applications through a single interface. This service provides multi-functional capabilities including authentication metadata generation, authorization metadata generation, and policy enforcement across different application types. By making the security infrastructure universal, the system reduces overall complexity while maintaining security across the enterprise application portfolio.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If authentication and authorization are tightly integrated with each application, then security control is precise, but ease of operation and maintenance deteriorate

Engineering Contradiction:
Improvesecurity control precisionVSAvoidmanagement ease
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent extracts the authentication and authorization logic from individual applications and consolidates it into a separate security metadata service. This extraction allows applications to maintain precise security control requirements while the complex authentication/authorization logic is managed centrally. The security metadata service receives requests from applications, processes them through standardized workflows, and returns appropriate metadata without requiring applications to contain embedded authentication logic.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The security metadata service acts as a mediator between applications and the authentication/authorization infrastructure. It provides a simplified interface for applications to request security metadata while handling the complex processing, policy evaluation, and metadata generation centrally. This intermediary layer improves ease of operation by providing a consistent, application-agnostic interface while maintaining precise security control through centralized management.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If separate authentication and authorization processes are implemented for each application, then security precision is maintained, but processing time and system performance decrease

Engineering Contradiction:
Improvesecurity precisionVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent merges the authentication and authorization processes into a unified security metadata service that handles both functions through a single interface. Instead of applications implementing separate authentication and authorization logic, the security metadata service combines these processes, generating both authentication and authorization metadata in a coordinated manner. This merging reduces redundant processing and improves overall system performance while maintaining security precision through centralized control.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The security metadata service performs preliminary processing of authentication and authorization requests by establishing standardized workflows and pre-configuring security policies. When an application requests security metadata, the service has already prepared the necessary processing frameworks, policy evaluations, and metadata templates in advance. This preliminary action reduces the actual processing time for each request while maintaining precise security control through pre-configured security rules.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8910048B2System and/or method for authentication and/or authorization
Publication Date: 2014.12.09 DISNEY ENTERPRISES INC
  • US8910048B2 patent drawing
  • US8910048B2 patent drawing
  • US8910048B2 patent drawing

AI summary

A computing platform constructs an application from source code such that the application detects an attempt to access at least one secured entity of the application. Further, the at least one secured entity is registered with an authorization system by providing metadata that is descriptive of the at least one secured entity to the authorization system so that authorization metadata is generated based upon the metadata and a global unique identifier is assigned to the application and the metadata to identify the application and the metadata. The authorization metadata indicates an access policy to the at least one secured entity.