Transactional Authorization System for Permission Consistency
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Large organizations face inconsistencies and unintended consequences due to multiple information systems managing employee data, leading to issues like lingering permissions, unpredictable behavior on manager changes, and incorrect returns from temporary assignments, resulting in flawed permissions and lack of consistent authorization across systems.
Innovation Solution
A transactional, constraint-based system comprising a Unified Identity Store, Administrative Hierarchy Store, and a Turing-complete domain-specific policy programming language to ensure consistent authorization across different software systems by correlating various representations of individuals, managing relational information, and computing changes based on constraints.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If multiple independent information systems are used to manage employee data, then each system can be optimized for its specific function, but inconsistencies and unintended consequences arise across systems leading to flawed permissions
Solution Approach 1:
The patent merges multiple independent information systems into a unified authorization system that centralizes permission management. This consolidation ensures consistent authorization states across all systems while maintaining the functional optimization of individual systems through standardized data interfaces and unified policy enforcement.
Solution Approach 2:
The patent creates a universal authorization system that serves multiple functions across different information systems. This single system handles employee data management, permission assignment, and authorization validation for various organizational functions, eliminating inconsistencies while providing versatile support for different operational needs.
2Reliability
If manual auditing of permissions is performed during employee transfers, then some permissions can be removed, but time-consuming oversight is required and permissions may still be unintentionally retained
Solution Approach 1:
The patent implements self-service automated permission management where the system automatically audits and updates permissions during employee transfers without requiring manual intervention. The unified authorization system monitors changes across all connected systems and automatically revokes or assigns permissions based on current organizational structure, eliminating time-consuming manual auditing while ensuring permission accuracy.
Solution Approach 2:
The patent establishes continuous feedback loops where the authorization system monitors employee status changes across all information systems and automatically adjusts permissions in real-time. This feedback mechanism ensures permission accuracy by continuously validating authorization states against current organizational data without requiring manual auditing cycles.
3Ease of operation
If complex business rules are duplicated across multiple systems, then each system can operate independently, but consistency and understanding of outcomes become difficult to maintain
Solution Approach 1:
The patent extracts business rules and authorization logic from multiple independent systems and consolidates them into a single unified authorization system. This extraction eliminates duplication while maintaining system independence through standardized interfaces, ensuring that business rule consistency is preserved without requiring each system to maintain separate copies of the same rules.
Data Source
AI summary
A new transactional, constraint-based system is provided to define and maintain authorization policies. Constraints are expressed as user-defined, domain-specific programs that operate on authoritative representations of entities and administrative hierarchies.


