Unified Authorization Model for Directory Services
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The complexity of managing inconsistent privilege sets across different products and services in information handling systems (IHS) leads to a significant burden for IT administrators, as each product and service requires distinct privilege objects, resulting in a cumbersome and difficult-to-manage authorization model.
Innovation Solution
A consistent authorization model is implemented by defining uniform roles and standard-based authorization profiles, where each product provides privilege sets associated with roles, reducing the need for multiple device and privilege objects, and allowing products and services to be represented by a single object, thereby simplifying the management of user roles and privileges.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Manufacturing precision
If distinct privilege objects are created for each product and service, then authorization precision is improved, but device complexity increases significantly
Solution Approach 1:
The patent implements a universal privilege object structure that can be applied across multiple products and services. Instead of creating distinct privilege objects for each product-service combination, a single privilege object can represent authorization across multiple targets, reducing the total number of objects while maintaining precise authorization control.
Solution Approach 2:
The patent merges the authorization model by combining product-specific and service-specific privileges into a unified privilege object structure. This consolidation reduces the number of discrete objects IT administrators must manage while preserving the ability to enforce granular authorization policies across different products and services.
2Measurement precision
If product-specific and service-specific privilege objects are created, then measurement precision of authorization is improved, but loss of time in management increases
Solution Approach 1:
The universal privilege object can simultaneously manage authorization across multiple products and services, eliminating the need to create and manage separate objects for each combination. This reduces the time required for authorization management while maintaining precise control over user access to specific products and services.
Solution Approach 2:
The patent establishes a standardized privilege object structure in advance that can be reused across different products and services. This preliminary definition of universal authorization templates eliminates the need to create new privilege objects for each product-service combination, significantly reducing management time while preserving authorization precision.
3Manufacturing precision
If multiple device objects and privilege objects are created for each product-service-role combination, then authorization precision is improved, but ease of operation deteriorates
Solution Approach 1:
The patent implements a universal privilege object that can associate a single user role with multiple products and services. Instead of requiring separate privilege objects for each product-service-role combination, the universal object allows IT administrators to define roles once and apply them across multiple targets, significantly improving ease of operation while maintaining authorization precision.
Solution Approach 2:
The patent segments the authorization model into universal privilege objects that can be independently configured and then applied to multiple product-service combinations. This segmentation allows administrators to manage authorization policies at a higher level of abstraction, making the system easier to operate while preserving fine-grained authorization control through the structured object relationships.
Data Source
AI summary
A method for managing authentication includes receiving a request at a directory service for authentication from a first of a plurality of users operating a first of a plurality of products, wherein the directory service associates each of the plurality of users with a plurality of roles for each of the plurality of products. The method also includes authenticating the first user utilizing the directory service, wherein the directory service provides a first role associated with the first user and the first product in response to the request.


