Semantic Tag Authorization Management for Hybrid Systems

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The complexity and cost of managing authorization across on-premise and on-demand modules in networked business applications increase due to differences in authorization schemes, making it challenging to provide seamless access and compliance across systems.

Innovation Solution

A method involving semantic tagging to map user requests to authorization decisions, using a semantic tag service provider and rules definitions to convert authorization schemes into a common language, enabling unified authorization management across on-premise and on-demand modules, and detecting segregation of duty violations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If multiple authorization schemes are used for on-premise and on-demand modules, then system functionality and flexibility are improved, but authorization management complexity increases

Engineering Contradiction:
Improveauthorization flexibilityVSAvoidauthorization management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces a semantic tag service provider as an intermediary layer between the authorization system and the modules. This mediator converts different authorization schemes (on-premise and on-demand) into a common semantic tag language, enabling unified authorization management without losing the flexibility of multiple schemes. The semantic tags act as a universal intermediary that bridges different authorization domains.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent transforms authorization decisions by changing the parameter representation from scheme-specific formats to standardized semantic tags. By mapping various authorization parameters (user roles, permissions, constraints) into a common semantic tag framework, the system maintains adaptability while reducing management complexity through parameter standardization.

Inventive Principle:
Principle #35Parameter changes

2Device complexity

If unified authorization management is implemented across on-premise and on-demand modules, then complexity is reduced, but adaptability to different authorization schemes may be limited

Engineering Contradiction:
Improveauthorization management complexityVSAvoidauthorization scheme flexibility
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The semantic tag service provider is designed with universal functionality to handle multiple authorization schemes simultaneously. It can process both on-premise and on-demand authorization requests using the same semantic tag framework, making the system universally applicable across different module types while maintaining their individual authorization characteristics.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent segments the authorization management into two independent layers: the semantic tag generation layer (which handles scheme-specific details) and the semantic tag processing layer (which provides unified management). This segmentation allows each layer to specialize - the generation layer maintains adaptability to different schemes while the processing layer provides simplified unified management.

Inventive Principle:
Principle #1Segmentation

3Productivity

If semantic tagging is used to map authorization requests, then processing efficiency is improved, but implementation complexity increases

Engineering Contradiction:
Improveauthorization processing efficiencyVSAvoidsemantic tag implementation complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The system performs preliminary action by pre-defining semantic tags and their mappings to various authorization schemes during system setup. This preliminary configuration work is done once, and then the semantic tags can be rapidly applied to authorization requests without repeated complex processing, thereby improving efficiency while the implementation complexity is confined to the initial setup phase.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9069984B2On-demand authorization management
Publication Date: 2015.06.30 SAP SE
  • US9069984B2 patent drawing
  • US9069984B2 patent drawing
  • US9069984B2 patent drawing

AI summary

Methods and apparatus, including computer program products, are provided for authorization management. In one aspect, there is provided a computer-implemented method. The method may include receiving a request to authorize at least one user to at least one module of a system; mapping the received request to a semantic tag; processing, based on the semantic tag, the request to authorize the at least one user to determine whether to grant the at least one user access to the at least one module; and sending a response to the request to authorize the at least one user, wherein the response is in accordance with the result of the processing. Related apparatus, systems, methods, and articles are also described.