Application Data Storage Area Generation for Role-Based Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Setting access authorities for application users in a user data storage area is time-consuming and often difficult due to the need for administrators to analyze directory and file structures, especially when dealing with multiple users and applications.
Innovation Solution
An application data storage area generation method that includes generating a data structure area for application data within a user data storage area, creating role information with access control settings, and associating user accounts with roles, thereby simplifying the process of setting access authorities.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Manufacturing precision
If administrators manually analyze directory and file structures to set access authorities, then access control can be accurately configured, but the process requires many man-hours and becomes time-consuming
Solution Approach 1:
The patent applies preliminary action by pre-defining role information and access control templates before actual access authority configuration. The system stores role information including access authorities for multiple users in advance, and automatically associates these pre-configured roles with users during application installation, eliminating the need for administrators to manually analyze directory structures at configuration time.
Solution Approach 2:
The system enables self-service by automatically generating access control configurations based on stored role information without requiring administrator intervention for manual analysis. The application data storage area generation automatically associates users with roles and configures access authorities based on pre-stored role definitions, making the system configure itself without human analysis of directory structures.
2Reliability
If detailed directory and file analysis is performed to properly set access authorities, then appropriate access control is achieved, but the complexity of the configuration process increases
Solution Approach 1:
The patent introduces role information as an intermediary between users and access control configurations. Instead of directly configuring access authorities for individual files and directories, the system uses pre-defined roles that encapsulate access control policies. This intermediary layer simplifies the configuration process while maintaining appropriate access control, as administrators only need to associate users with roles rather than manually configuring each access permission.
Solution Approach 2:
The system segments access control configuration into separate, manageable components: role information definitions and user-role associations. By dividing the complex task of access authority configuration into these discrete segments, the system reduces overall complexity while ensuring comprehensive and appropriate access control through the structured role-based approach.
3Reliability
If access authorities are configured for multiple users in a shared storage area, then proper access control is established, but the setup process becomes difficult and time-consuming
Solution Approach 1:
The patent applies universality by creating role information that serves multiple users simultaneously with similar access requirements. Instead of configuring access authorities individually for each user, the system defines universal role profiles that can be associated with multiple users, making the access control setup process easier while maintaining proper access control establishment for all users in the shared storage area.
Data Source
AI summary
An application data storage area generation method that is executed by a processor includes, (a) generating an application data storage area including a data structure area where data of an application is stored, in a user data storage area shared by a plurality of user accounts, in response to a utilization request for the application, (b) generating, in the user data storage area, role information including a plurality of roles for which access control information on access to a data structure of the application is set, and (c) storing, in the user data storage area, information on association between the plurality of user accounts and the plurality of roles included in the role information.


