URL Query String Access Rule Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing access management systems face challenges in scaling to handle increasing volumes of users and content, making it difficult to manage access rules across numerous resources, leading to operational inefficiencies and potential security vulnerabilities.

Innovation Solution

A system that utilizes query data from URLs to identify appropriate access rules, allowing for the grouping of resources and application of access rules based on order-dependent or independent variables, with two levels of rules for centralized management and decentralized administration.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Quantity of substance

If access management systems are scaled to handle increasing volumes of users and content, then the system capacity and coverage are improved, but the complexity of managing access rules across numerous resources increases

Engineering Contradiction:
Improvevolume of users and contentVSAvoidcomplexity of managing access rules
Core Design Contradiction:
Quantity of substanceVSDevice complexity

Solution Approach 1:

The patent segments access rules into two hierarchical levels: first-level rules that apply broadly to groups of resources, and second-level rules that apply to specific individual resources. This segmentation allows the system to scale to numerous resources while maintaining manageable rule complexity by organizing rules in a structured hierarchy rather than requiring separate rules for every resource.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates universal first-level access rules that can apply to multiple resources simultaneously. A single first-level rule can cover entire groups of resources, allowing the system to manage access for large volumes of users and content through a small number of generalized rules, thereby reducing the overall complexity of access rule management.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Manufacturing precision

If separate access rules are created for each individual resource, then the precision of access control is improved, but the administrative effort and time required to manage rules increases

Engineering Contradiction:
Improveprecision of access controlVSAvoidadministrative effort and time
Core Design Contradiction:
Manufacturing precisionVSLoss of time

Solution Approach 1:

The patent divides access control into two levels: first-level rules for broad resource groups and second-level rules for specific resources. This segmentation enables precise control at the second level while reducing administrative burden through the generalized first-level rules that cover multiple resources, eliminating the need to create separate rules for every individual resource.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent establishes first-level access rules in advance that apply to groups of resources before specific second-level rules are needed. This preliminary action of creating general rules upfront reduces the time and effort required for ongoing access control management, as administrators can quickly apply pre-defined first-level rules rather than creating individual rules for each resource.

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If two levels of access rules are implemented for centralized management, then the ease of administration is improved, but the device complexity increases

Engineering Contradiction:
Improveease of administrationVSAvoidsystem structure complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent segments the access rule management system into two distinct levels: first-level rules for centralized management of resource groups and second-level rules for specific resources. This segmentation provides a clear hierarchical structure that simplifies administration by organizing rules logically, making it easier to manage access across numerous resources while the structured hierarchy helps manage the inherent system complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The first-level rules act as an intermediary layer between the administrators and the numerous individual resources. This intermediary structure simplifies administration by providing a intermediate level of abstraction that manages groups of resources collectively, reducing the direct complexity of managing each individual resource while maintaining centralized control.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8204999B2Query string processing
Publication Date: 2012.06.19 ORACLE INT CORP
  • US8204999B2 patent drawing
  • US8204999B2 patent drawing
  • US8204999B2 patent drawing

AI summary

A system is disclosed that is used to provide access management for resources on a network. The system makes use of query data from a URL (or another identification or request) to identify the appropriate access rule. Examples of an access rule include an authentication rule, an authorization rule, or an audit rule. The system can be configured to require the query data to match order dependent variables or order independent variables. In one option, the system can include two levels of rules and the query data can be used to identify first level rules, second level rules or both.