Super Role Definition System for Granular Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing access control systems, such as J2EE and WebSphere™, lack flexibility and granularity in managing permissions for individual resource instances, leading to complex administration and increased likelihood of errors, especially when dealing with hierarchical resource structures.
Innovation Solution
The introduction of a role-based access control system that includes super roles, which aggregate individual roles and allow for dynamic assignment, nesting, and inheritance, providing a higher level of semantic roles that can manage permissions across multiple resource hierarchies, thereby simplifying administration and reducing errors.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Manufacturing precision
If classical access control lists (ACL) are used to manage permissions, then fine-grained control over permission levels is achieved, but the complexity of configuring and changing permissions increases significantly
Solution Approach 1:
The patent combines multiple individual permissions into role-based access control structures. Instead of managing permissions individually through ACLs, the system merges related permissions into roles that can be assigned to users collectively, reducing administrative complexity while maintaining fine-grained control capabilities.
Solution Approach 2:
The patent introduces role templates that can be universally applied across multiple resources and users. A single role template can define a set of permissions that are then reused across different contexts, eliminating the need to configure identical permission sets repeatedly and reducing overall system complexity.
2Ease of operation
If role-based access control is implemented without instance-level protection, then administration is simplified, but the ability to enforce different access control constraints on individual resource instances is lost
Solution Approach 1:
The patent segments access control into two distinct layers: role templates that define permission sets (providing administrative simplicity) and role assignments that bind these templates to specific resource instances (enabling instance-level control). This segmentation allows each layer to fulfill its specific function without compromising the other.
Solution Approach 2:
The patent implements a nested structure where role templates contain permission definitions, which are then nested within role assignments that specify resource instances. This nested architecture allows instance-level protection to be built upon the foundation of simplified role-based control, with each nesting level adding specific functionality.
3Reliability
If permissions are managed at the resource instance level, then security is improved, but the complexity of permission management increases
Solution Approach 1:
The patent performs preliminary action by pre-defining role templates with appropriate permission sets before they are assigned to resources. This preliminary configuration of permissions in a standardized format reduces the complexity of subsequent instance-level assignments, as administrators only need to reference existing templates rather than create permissions from scratch for each instance.
Data Source
AI summary
The invention relates to a role-based access control system, including a role definition system for defining roles to be sets of permissions on individual resources thus forming role instances, respectively; and a super role definition system for defining at least one super role by grouping a set of role instances into one super role, wherein the one super role contains all permissions contained in the grouped resource instances. Furthermore, the present invention deals with an appropriate method, a computer program and a computer program product.


