Semantic Tag Authorization Management for Hybrid Systems
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The complexity and cost of managing authorization across on-premise and on-demand modules in networked business applications increase due to differences in authorization schemes, making it challenging to provide seamless access and compliance across systems.
Innovation Solution
A method involving semantic tagging to map user requests to authorization decisions, using a semantic tag service provider and rules definitions to convert authorization schemes into a common language, enabling unified authorization management across on-premise and on-demand modules, and detecting segregation of duty violations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If multiple authorization schemes are used for on-premise and on-demand modules, then system functionality and flexibility are improved, but authorization management complexity increases
Solution Approach 1:
The patent introduces a semantic tag service provider as an intermediary layer between the authorization system and the modules. This mediator converts different authorization schemes (on-premise and on-demand) into a common semantic tag language, enabling unified authorization management without losing the flexibility of multiple schemes. The semantic tags act as a universal intermediary that bridges different authorization domains.
Solution Approach 2:
The patent transforms authorization decisions by changing the parameter representation from scheme-specific formats to standardized semantic tags. By mapping various authorization parameters (user roles, permissions, constraints) into a common semantic tag framework, the system maintains adaptability while reducing management complexity through parameter standardization.
2Device complexity
If unified authorization management is implemented across on-premise and on-demand modules, then complexity is reduced, but adaptability to different authorization schemes may be limited
Solution Approach 1:
The semantic tag service provider is designed with universal functionality to handle multiple authorization schemes simultaneously. It can process both on-premise and on-demand authorization requests using the same semantic tag framework, making the system universally applicable across different module types while maintaining their individual authorization characteristics.
Solution Approach 2:
The patent segments the authorization management into two independent layers: the semantic tag generation layer (which handles scheme-specific details) and the semantic tag processing layer (which provides unified management). This segmentation allows each layer to specialize - the generation layer maintains adaptability to different schemes while the processing layer provides simplified unified management.
3Productivity
If semantic tagging is used to map authorization requests, then processing efficiency is improved, but implementation complexity increases
Solution Approach 1:
The system performs preliminary action by pre-defining semantic tags and their mappings to various authorization schemes during system setup. This preliminary configuration work is done once, and then the semantic tags can be rapidly applied to authorization requests without repeated complex processing, thereby improving efficiency while the implementation complexity is confined to the initial setup phase.
Data Source
AI summary
Methods and apparatus, including computer program products, are provided for authorization management. In one aspect, there is provided a computer-implemented method. The method may include receiving a request to authorize at least one user to at least one module of a system; mapping the received request to a semantic tag; processing, based on the semantic tag, the request to authorize the at least one user to determine whether to grant the at least one user access to the at least one module; and sending a response to the request to authorize the at least one user, wherein the response is in accordance with the result of the processing. Related apparatus, systems, methods, and articles are also described.


