Super Role Definition System for Granular Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing access control systems, such as J2EE and WebSphere™, lack flexibility and granularity in managing permissions for individual resource instances, leading to complex administration and increased likelihood of errors, especially when dealing with hierarchical resource structures.

Innovation Solution

The introduction of a role-based access control system that includes super roles, which aggregate individual roles and allow for dynamic assignment, nesting, and inheritance, providing a higher level of semantic roles that can manage permissions across multiple resource hierarchies, thereby simplifying administration and reducing errors.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Manufacturing precision

If classical access control lists (ACL) are used to manage permissions, then fine-grained control over permission levels is achieved, but the complexity of configuring and changing permissions increases significantly

Engineering Contradiction:
Improvepermission control granularityVSAvoidaccess control administration complexity
Core Design Contradiction:
Manufacturing precisionVSDevice complexity

Solution Approach 1:

The patent combines multiple individual permissions into role-based access control structures. Instead of managing permissions individually through ACLs, the system merges related permissions into roles that can be assigned to users collectively, reducing administrative complexity while maintaining fine-grained control capabilities.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent introduces role templates that can be universally applied across multiple resources and users. A single role template can define a set of permissions that are then reused across different contexts, eliminating the need to configure identical permission sets repeatedly and reducing overall system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Ease of operation

If role-based access control is implemented without instance-level protection, then administration is simplified, but the ability to enforce different access control constraints on individual resource instances is lost

Engineering Contradiction:
Improveaccess control administration easeVSAvoidinstance-level access control capability
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The patent segments access control into two distinct layers: role templates that define permission sets (providing administrative simplicity) and role assignments that bind these templates to specific resource instances (enabling instance-level control). This segmentation allows each layer to fulfill its specific function without compromising the other.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements a nested structure where role templates contain permission definitions, which are then nested within role assignments that specify resource instances. This nested architecture allows instance-level protection to be built upon the foundation of simplified role-based control, with each nesting level adding specific functionality.

Inventive Principle:
Principle #7Nested doll (Nesting)

3Reliability

If permissions are managed at the resource instance level, then security is improved, but the complexity of permission management increases

Engineering Contradiction:
Improvesecurity control reliabilityVSAvoidpermission management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent performs preliminary action by pre-defining role templates with appropriate permission sets before they are assigned to resources. This preliminary configuration of permissions in a standardized format reduces the complexity of subsequent instance-level assignments, as administrators only need to reference existing templates rather than create permissions from scratch for each instance.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9032076B2Role-based access control system, method and computer program product
Publication Date: 2015.05.12 DAEDALUS BLUE LLC
  • US9032076B2 patent drawing
  • US9032076B2 patent drawing
  • US9032076B2 patent drawing

AI summary

The invention relates to a role-based access control system, including a role definition system for defining roles to be sets of permissions on individual resources thus forming role instances, respectively; and a super role definition system for defining at least one super role by grouping a set of role instances into one super role, wherein the one super role contains all permissions contained in the grouped resource instances. Furthermore, the present invention deals with an appropriate method, a computer program and a computer program product.