Self-Service Source Architecture for Secure Enterprise Search

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing search systems face challenges in securely accessing and indexing enterprise data due to complex dynamic security hierarchies and varying security mechanisms, making it difficult to provide authorized access across disparate systems like eBusiness or PEOPLESOFT applications.

Innovation Solution

A flexible and extensible architecture that enables authentication, authorization, and secure enterprise search, allowing for real-time access to secure content by submitting security attributes at query time, and providing dynamic querying and suggested content relevant to user queries.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Quantity of substance

If traditional crawling is used to index enterprise data, then search coverage is improved, but security control deteriorates because crawlers cannot enforce dynamic security hierarchies across disparate systems

Engineering Contradiction:
Improvesearch coverageVSAvoidsecurity control
Core Design Contradiction:
Quantity of substanceVSReliability

Solution Approach 1:

The patent introduces a self-service source mechanism that acts as an intermediary between the crawler and secure enterprise data sources. This source provides credentials and security attributes to the crawler, enabling it to access and index data from multiple disparate systems while maintaining security control. The self-service source mediates the authentication and authorization process, allowing the crawler to operate securely across systems with different security mechanisms.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If security credentials are stored for crawling, then access to secure sources is improved, but security risk deteriorates due to potential credential exposure

Engineering Contradiction:
Improveaccess to secure sourcesVSAvoidcredential exposure risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent implements temporary credentials with minimum lifespan requirements that are generated on-demand for crawling operations. These credentials have limited validity periods and are discarded after use, eliminating the need for long-term credential storage. The self-service source generates fresh credentials as needed, ensuring that even if compromised, the exposure window is minimal. This approach enables secure access while minimizing security risks associated with credential management.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

3Ease of operation

If user role models are used for authorization, then access control is simplified, but adaptability deteriorates because they cannot handle dynamic security hierarchies across different applications

Engineering Contradiction:
Improveaccess control simplicityVSAvoidhandling dynamic security hierarchies
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The patent transitions from static user role models to dynamic security attribute-based authorization. The self-service source provides security attributes that are evaluated in real-time during crawling operations, allowing the system to adapt to changing security requirements across different applications. This dynamic approach maintains simplicity by automating the evaluation process while significantly improving adaptability to various security hierarchies and access control policies.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS8027982B2Self-service sources for secure search
Publication Date: 2011.09.27 ORACLE INT CORP
  • US8027982B2 patent drawing
  • US8027982B2 patent drawing
  • US8027982B2 patent drawing

AI summary

A flexible and extensible architecture allows for secure searching across an enterprise. Such an architecture can provide a simple Internet-like search experience to users searching secure content inside (and outside) the enterprise. The architecture allows for the crawling and searching of a variety of sources across an enterprise, regardless of whether any of these sources conform to a conventional user role model. The architecture further allows for security attributes to be submitted at query time, for example, in order to provide real-time secure access to enterprise resources. The user query also can be transformed to provide for dynamic querying that provides for a more current result list than can be obtained for static queries.