Access Rights Management Interface for Web Application Design

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Designing and maintaining database-driven web applications with multiple user roles and rights is complex, as pages behave differently based on submitted data and user access, making it difficult for application owners to comprehend and verify application behavior.

Innovation Solution

A computer-implemented design interface that provides a workflow inference, summarization, and visualization of data flows, allowing designers to simulate user interactions and understand access rights modifications, and generates application queries and commands to enforce access rights based on user actions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a web application is designed with multiple user roles and complex access rights, then the application functionality and security are improved, but the complexity of designing and maintaining the application increases

Engineering Contradiction:
Improveaccess rights enforcementVSAvoidapplication design complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary component (access rights management system) that mediates between users and application resources. This intermediary automatically enforces access rights based on user roles and actions, reducing the complexity of manual access control design while improving security and reliability of access rights enforcement.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary actions by pre-defining user roles, access rights, and action specifications during application design. Access rights modifications are predetermined and automatically applied when specific actions are invoked, eliminating the need for complex runtime access control decisions and simplifying maintenance.

Inventive Principle:
Principle #10Preliminary action

2Adaptability or versatility

If access rights modifications are dynamically applied based on user actions, then the application adaptability is improved, but the difficulty of verifying application behavior increases

Engineering Contradiction:
Improveaccess rights adaptabilityVSAvoidbehavior verification difficulty
Core Design Contradiction:
Adaptability or versatilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent implements feedback mechanisms that automatically track and record access rights modifications triggered by user actions. The system provides feedback loops that verify whether access rights changes were correctly applied, enabling automatic validation of application behavior and reducing the difficulty of verifying dynamic access control operations.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system creates copies of access rights specifications and action definitions that can be independently verified and tested. By maintaining copies of the intended access rights modifications alongside the actual application state, the system enables verification of behavior without interfering with the dynamic adaptability of access control.

Inventive Principle:
Principle #26Copying

3Productivity

If the application state is modified by user actions with different access rights, then the application functionality is improved, but the complexity of managing and enforcing access rights increases

Engineering Contradiction:
Improveapplication functionalityVSAvoidaccess rights management complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent segments access rights management into distinct components: user roles, access rights definitions, action specifications, and enforcement mechanisms. This segmentation allows each component to be independently managed and configured, reducing the overall complexity of managing access rights while enabling rich application functionality with multiple user roles and permissions.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS8898623B2Application design and data flow analysis
Publication Date: 2014.11.25 RGT UNIV OF CALIFORNIA
  • US8898623B2 patent drawing
  • US8898623B2 patent drawing
  • US8898623B2 patent drawing

AI summary

Techniques, apparatuses, and systems for application design and application data flow analysis. Techniques, apparatuses, and systems can include providing a design interface to create an application with different user groups and access rights, the design interface operable to specify an action to include to a page of the application, where the action, when invoked, modifies the application state; receiving an action specification that describes an access rights modification that results from an invocation of the action during an execution of the application, where the access rights modification indicates an enabling or disabling of one or more access rights of a user; and generating application specification queries and commands to enforce access rights based on the access rights modification.