Authority Delegation for Business Object Attachments

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing computer systems face challenges in simplifying user authority and access control for business object attachments across diverse computing environments, particularly in cloud and mobile scenarios, where direct and indirect security mechanisms complicate authorization processes.

Innovation Solution

A content management interface layer is introduced to mediate user authorization checks by identifying the originating system of a business object attachment and sending semantic values for authority checks, allowing secure access and manipulation of business object attachments based on predefined business object authorities stored in an Enterprise Resource Planning system.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If direct security checks of user credentials are conducted at the attachment interface before users can access business object attachments, then security control is improved, but device complexity and authorization process complexity increase

Engineering Contradiction:
Improvesecurity controlVSAvoidauthorization process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary authorization mechanism that mediates between the user and the attachment interface. Instead of conducting direct security checks at the attachment interface, the system uses an intermediary layer that handles authorization requests by evaluating user credentials against business object authorities and attachment security settings. This intermediary approach maintains security control while simplifying the overall authorization process by centralizing the security check logic.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If ACL-based security models are deployed to govern user access to business objects and their attachments, then security control is improved, but ease of operation deteriorates due to complex authorization checks

Engineering Contradiction:
Improvesecurity controlVSAvoiduser access simplicity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent applies preliminary action by pre-establishing business object authorities and attachment security settings before users attempt to access attachments. The system pre-configures ACL entries that define user permissions for both business objects and their attachments. When users request access, the pre-configured authorities are automatically evaluated, eliminating the need for complex real-time authorization checks and simplifying the user experience while maintaining security control.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If user authorities are established for diverse business objects in large computer systems, then security control is improved, but device complexity increases due to managing authorities across multiple systems

Engineering Contradiction:
Improvesecurity controlVSAvoidauthority management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements universality by creating a unified authority management framework that works across diverse business objects and multiple computer systems. The system uses a universal ACL-based security model that can govern access to business objects regardless of their specific type or location. This universal approach allows the same authorization mechanisms to be applied consistently across finance, HR, manufacturing, and other business domains, reducing the complexity of managing authorities across multiple systems while maintaining comprehensive security control.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS8832856B2Authority delegation for business objects
Publication Date: 2014.09.09 SAP SE
  • US8832856B2 patent drawing
  • US8832856B2 patent drawing
  • US8832856B2 patent drawing

AI summary

A method relates to authority checks governing user access to business object attachments in a store of business object attachments. The business object attachments are semantically associated with business objects of one or more remote computer systems. The method includes, at a content management interface layer that is communicatively coupled to the store of business object attachments, sending a request for user authority checks on a parent business object of a business object attachment to an originating computer system and receiving results of the user authority checks from the originating computer system.