Application Data Storage Area Generation for Role-Based Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Setting access authorities for application users in a user data storage area is time-consuming and often difficult due to the need for administrators to analyze directory and file structures, especially when dealing with multiple users and applications.

Innovation Solution

An application data storage area generation method that includes generating a data structure area for application data within a user data storage area, creating role information with access control settings, and associating user accounts with roles, thereby simplifying the process of setting access authorities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Manufacturing precision

If administrators manually analyze directory and file structures to set access authorities, then access control can be accurately configured, but the process requires many man-hours and becomes time-consuming

Engineering Contradiction:
Improveaccess authority configuration accuracyVSAvoidtime required for access authority setting
Core Design Contradiction:
Manufacturing precisionVSLoss of time

Solution Approach 1:

The patent applies preliminary action by pre-defining role information and access control templates before actual access authority configuration. The system stores role information including access authorities for multiple users in advance, and automatically associates these pre-configured roles with users during application installation, eliminating the need for administrators to manually analyze directory structures at configuration time.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system enables self-service by automatically generating access control configurations based on stored role information without requiring administrator intervention for manual analysis. The application data storage area generation automatically associates users with roles and configures access authorities based on pre-stored role definitions, making the system configure itself without human analysis of directory structures.

Inventive Principle:
Principle #25Self-service

2Reliability

If detailed directory and file analysis is performed to properly set access authorities, then appropriate access control is achieved, but the complexity of the configuration process increases

Engineering Contradiction:
Improveaccess control appropriatenessVSAvoidconfiguration process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces role information as an intermediary between users and access control configurations. Instead of directly configuring access authorities for individual files and directories, the system uses pre-defined roles that encapsulate access control policies. This intermediary layer simplifies the configuration process while maintaining appropriate access control, as administrators only need to associate users with roles rather than manually configuring each access permission.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system segments access control configuration into separate, manageable components: role information definitions and user-role associations. By dividing the complex task of access authority configuration into these discrete segments, the system reduces overall complexity while ensuring comprehensive and appropriate access control through the structured role-based approach.

Inventive Principle:
Principle #1Segmentation

3Reliability

If access authorities are configured for multiple users in a shared storage area, then proper access control is established, but the setup process becomes difficult and time-consuming

Engineering Contradiction:
Improveaccess control establishmentVSAvoidaccess authority setting ease
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent applies universality by creating role information that serves multiple users simultaneously with similar access requirements. Instead of configuring access authorities individually for each user, the system defines universal role profiles that can be associated with multiple users, making the access control setup process easier while maintaining proper access control establishment for all users in the shared storage area.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10102396B2Application data storage area generation method, application data storage area generation apparatus, and application data storage area generation program
Publication Date: 2018.10.16 FUJITSU LTD
  • US10102396B2 patent drawing
  • US10102396B2 patent drawing
  • US10102396B2 patent drawing

AI summary

An application data storage area generation method that is executed by a processor includes, (a) generating an application data storage area including a data structure area where data of an application is stored, in a user data storage area shared by a plurality of user accounts, in response to a utilization request for the application, (b) generating, in the user data storage area, role information including a plurality of roles for which access control information on access to a data structure of the application is set, and (c) storing, in the user data storage area, information on association between the plurality of user accounts and the plurality of roles included in the role information.