Workflow Access Control Matrix with Logical Roles
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional Role-Based Access Control (RBAC) systems provide coarse-grain access control, which is not adequate for meeting user needs or providing customizable solutions in workflows, as they do not consider a user's status or responsibility relative to specific tasks.
Innovation Solution
A system and method that combines RBAC with a configurable matrix of access controls based on logical roles and user responsibilities, allowing for fine-grain access control by considering a user's status and task-specific data or events, enabling customizable access rights for tasks within workflows.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If traditional Role-Based Access Control (RBAC) systems are used, then access control is simple to implement, but the access control granularity is too coarse to meet user needs
Solution Approach 1:
The patent segments access control into two distinct layers: traditional RBAC roles for basic authorization and dynamic logical roles for fine-grained task-specific control. This segmentation allows the system to maintain the simplicity of RBAC while adding the granularity of task-specific roles, resolving the contradiction between ease of implementation and access control precision.
Solution Approach 2:
The patent adds a temporal dimension to access control by introducing task-state-dependent logical roles. Instead of static role assignments, the system dynamically creates roles based on current task states, user responsibilities, and workflow context. This dimensional addition enables fine-grained control without complicating the underlying RBAC structure.
2Manufacturing precision
If fine-grain access control is implemented considering user status and task-specific data, then access control precision is improved, but system complexity increases
Solution Approach 1:
The patent introduces logical roles as intermediary entities that bridge the gap between static RBAC roles and dynamic task requirements. These logical roles act as mediators that are created temporarily based on task state and user responsibility, enabling precise access control without directly modifying the core RBAC system structure, thus managing complexity.
Solution Approach 2:
The system implements dynamic role creation and deletion based on task state changes. Logical roles are created when needed for specific task instances and automatically removed when no longer required. This dynamic approach enables high precision access control while keeping the system adaptable and manageable, as roles are created on-demand rather than being statically defined.
3Adaptability or versatility
If dynamic access controls are applied to different task instances, then customization capability is improved, but processing overhead increases
Solution Approach 1:
The system performs preliminary actions by pre-defining the structure and rules for logical roles before task execution. Role templates and access control policies are established in advance, allowing the system to quickly instantiate appropriate roles when tasks are created without performing complex calculations during task execution, thus maintaining processing efficiency while enabling customization.
Solution Approach 2:
The patent changes parameters by using task state values as dynamic inputs for role creation. Instead of hardcoding role assignments, the system parameters (role definitions, access permissions) are dynamically adjusted based on task state, user responsibility, and workflow context. This parameter-driven approach enables high customization while maintaining processing efficiency through systematic parameter management.
Data Source
AI summary
A system for providing complex access control in workflows. The system comprises a computer, including a computer readable storage medium and processor operating thereon. The system also comprises at least one business process which includes a plurality of tasks. Each task is associated with a task state which changes during execution of the task. The system further comprises a plurality of logical roles. Each logical role defines a responsibility based on the task state and a member of that logical role. Additionally, the system comprises a configurable matrix of access controls that is used to control access to the plurality of tasks based on the plurality of logical roles.


