Hierarchical Web App Security Configuration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Web application security configurations in cloud-based enterprise software-as-a-service solutions are challenging to manage, particularly when new functionalities are added, as each tenant must reconfigure security settings according to their business practices and services, leading to complexity and inefficiency.

Innovation Solution

A system implements qualified web application security based on a hierarchy that identifies user roles, subscriptions, and device types to create executable files that enforce access permissions, allowing only authorized functionalities to be accessed, thereby simplifying security configuration and management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional web application security configuration is used, then security control is achieved, but configuration complexity and management difficulty increase significantly

Engineering Contradiction:
Improvesecurity controlVSAvoidconfiguration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the web application functionality into a hierarchical structure with parent nodes representing functional categories and child nodes representing specific functionalities. Each node can have its own security configuration, allowing granular control while maintaining organization. This segmentation enables tenants to configure security at different levels of the hierarchy, reducing overall configuration complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements a nested hierarchy where child nodes inherit security configurations from parent nodes unless explicitly overridden. This nesting mechanism allows security policies to be defined at high levels and automatically applied to subordinate functionalities, reducing the number of individual configurations needed while maintaining comprehensive security control.

Inventive Principle:
Principle #7Nested doll (Nesting)

2Reliability

If security configurations are updated to accommodate new functionalities, then security coverage is improved, but configuration time and effort increase

Engineering Contradiction:
Improvesecurity coverageVSAvoidconfiguration time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent allows tenants to pre-configure security policies at parent nodes that automatically apply to multiple child nodes. When new functionalities are added to the hierarchy, the pre-defined security configurations at parent levels are automatically inherited, eliminating the need for reconfiguration. This preliminary action significantly reduces configuration time while maintaining comprehensive security coverage.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent creates a universal security configuration framework where a single security policy at a parent node can govern multiple child nodes and functionalities. This multi-functionality allows one configuration to serve multiple purposes, reducing the total configuration effort required when new functionalities are introduced while ensuring broad security coverage.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Adaptability or versatility

If tenant-specific security configurations are implemented, then security customization is achieved, but management difficulty increases

Engineering Contradiction:
Improvesecurity customizationVSAvoidmanagement ease
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent implements a dynamic inheritance model where security configurations automatically adapt to the hierarchical structure. Tenant-specific policies defined at parent nodes dynamically apply to child nodes, and the system automatically adjusts access control based on user roles and the hierarchical relationships. This dynamic behavior maintains customization while simplifying management through automatic propagation.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent enables the security system to self-configure and self-manage by automatically inheriting and applying security policies across the hierarchy. When tenants define security configurations at parent nodes, the system automatically propagates these configurations to child nodes without requiring manual intervention. This self-service capability maintains tenant-specific customization while dramatically reducing management complexity.

Inventive Principle:
Principle #25Self-service

4Measurement precision

If detailed security configurations are provided for each functionality, then access control precision is improved, but system complexity increases

Engineering Contradiction:
Improveaccess control precisionVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the access control system into a hierarchical structure where security policies are defined at different levels. This segmentation allows precise access control to be achieved through targeted policies at specific nodes while maintaining overall system simplicity through the organized hierarchy. The segmented structure makes it easier to manage and understand access control rules.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies local quality by allowing different security policies to be defined at different levels of the hierarchy according to local requirements. Parent nodes can have broad policies while child nodes have specific policies, creating a gradient of specificity that achieves precise access control without requiring detailed configurations throughout the entire system. This localized approach to quality maintains precision while reducing overall complexity.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS10079831B1Qualified web application security based on web application hierarchy
Publication Date: 2018.09.18 EMC IP HLDG CO LLC
  • US10079831B1 patent drawing
  • US10079831B1 patent drawing
  • US10079831B1 patent drawing

AI summary

Qualified web application security based on web application hierarchy is described. A system receives a web application login request from a web browser associated with a user device. The system identifies qualified user information associated with the user device. The system creates an executable file based on applying the qualified user information to a web application hierarchy file comprising hierarchical nodes, wherein each of the hierarchical nodes is associated with a corresponding web application function, at least one corresponding business rule, and a corresponding scope-based security configuration. The system sends the executable file to the web browser, thereby enabling the web browser to apply qualified web application security to requests from the user device for accessing the web application.