Security Migration System for Business Intelligence Environments

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Business Intelligence (BI) environments face challenges in seamlessly migrating identity information and managing access when external security sources are replaced, repaired, or merged, leading to issues with local identifiers and security principal validation, which can be cumbersome, expensive, and error-prone.

Innovation Solution

A Security Migration System (SMS) is introduced to manage access by generating a mapping of local identifiers, allowing access independent of the original namespace, and delegating validation to external security sources, enabling continued access based on previously generated local identifiers even when the original namespace is replaced or restricted.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If external security sources are replaced or restricted, then security management flexibility is improved, but access continuity deteriorates

Engineering Contradiction:
Improvesecurity management flexibilityVSAvoidaccess continuity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces a namespace as an intermediary layer between the BI environment and external security sources. This namespace stores local identifiers that can resolve to security principals from different external security sources, allowing the system to maintain access continuity even when external security sources are replaced or restricted. The namespace acts as a buffer that decouples the BI environment from direct dependencies on specific external security sources.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If local identifiers are regenerated when namespace changes, then security validation accuracy is improved, but system complexity and error potential increase

Engineering Contradiction:
Improvesecurity validation accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent pre-generates and stores local identifiers in the namespace before external security source changes occur. These local identifiers are cached and can be resolved to security principals from different external security sources as needed. This preliminary action eliminates the need to regenerate identifiers during namespace changes, reducing system complexity and error potential while maintaining security validation accuracy.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If extensive modifications are made in BI environment during namespace migration, then security migration completeness is improved, but migration cost and time increase

Engineering Contradiction:
Improvesecurity migration completenessVSAvoidmigration time
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The patent creates a copy of the security principal information in the namespace, storing local identifiers that reference security principals from external security sources. This copying approach allows the BI environment to maintain access using the copied identifiers without requiring extensive modifications during migration. The namespace handles the resolution to the actual security principals, enabling seamless migration with minimal disruption to the BI environment.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS11451529B2Security migration in a business intelligence environment
Publication Date: 2022.09.20 MOTIO
  • US11451529B2 patent drawing
  • US11451529B2 patent drawing
  • US11451529B2 patent drawing

AI summary

In various implementations, local identifiers associated with users may be utilized to enable access one or more functions in a Business Intelligence (BI) Environment. A mapping may be generated to associate local identifiers and users. The mapping may be utilized to enable access in the BI environment by retrieving the local identifier from a mapping and enabling access in the BI environment based on the local identifier. In various implementations, a user may access the system as another user.