Structure-Based Authentication for Granular Resource Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing single sign-on (SSO) techniques rely on predefined roles to manage resource access, which can lead to inflexibility and mismatches between user permissions and resource structures, necessitating coordinated role definitions across identity and service provider systems.
Innovation Solution
An identity provider system determines a permission indication based on the structure of resources at the service provider system, specifying the subset of resources a user is permitted to access, allowing for flexible and granular permission management without preconfigured roles.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If predefined roles are used to manage resource access, then access control is simplified, but flexibility and precision in permission allocation deteriorate
Solution Approach 1:
The patent changes the parameter of permission representation from fixed role-based categories to granular, structure-based parameters. Instead of assigning users to predefined roles, the system defines permissions by specifying exact portions of resource structures (tables, fields, rows) that users can access, allowing flexible and precise control over data access rights.
Solution Approach 2:
The patent segments resource access permissions into fine-grained units corresponding to specific portions of the resource structure. Rather than granting access at the role level, the system divides permissions down to the level of individual tables, fields, and rows, enabling precise control over which specific data elements users can access.
2Device complexity
If role-based access control is used, then system complexity is reduced, but alignment with actual resource structure deteriorates
Solution Approach 1:
The patent inverts the traditional role-based approach by starting with the resource structure itself and deriving permissions from it, rather than starting with predefined roles and mapping resources to them. This inversion ensures that permissions naturally align with the actual database structure without requiring coordinated role definitions across multiple systems.
3Productivity
If single sign-on uses predefined roles, then authentication is streamlined, but permission precision deteriorates
Solution Approach 1:
The patent introduces dynamic permission specification where the permission indication can define different portions of the resource structure based on the authenticated user's characteristics. This allows the system to maintain efficient single sign-on authentication while enabling precise, user-specific permission allocation that adapts to individual user needs rather than relying on static role definitions.
Data Source
AI summary
Methods performed by an identity provider system, a service provider system and a user device are provided. The identity provider system performs an authentication process to confirm an identity of a user. In a case that the identity of the user is confirmed by the authentication process, the identity provider system determines a portion of resources made available at the service provider system that the user is allocated permission to access and generates a permission indication. The permission indication defines a portion of a structure of the resources corresponding to the portion of the resources which the user is permitted to access. The user can access resources made available by the service provider system which are both requested by user device via a resource request and permitted to be accessed by the user according to the permission indication.


