Authorized Role Prediction and Registration for ERP Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing ERP systems face challenges in efficiently determining and managing authorized roles due to the complexity arising from organization-dependent factors such as size, security levels, and number of owners, leading to delays in granting or denying access to enterprise resources.

Innovation Solution

An authorized roles tool utilizing a data management model generated through machine learning techniques to predict and register unregistered actions and permissions, automating the role assignment process.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual role definition and access management is performed in ERP systems, then security and protection of enterprise resources is ensured, but the complexity of defining roles increases significantly due to organization-dependent factors such as size, security levels, and number of owners

Engineering Contradiction:
Improvesecurity and protectionVSAvoidcomplexity of defining roles
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system automatically determines authorized roles by analyzing user profiles, system configurations, and enterprise resources without requiring manual intervention. The role determination is performed autonomously by the processor executing the patent's methodology, eliminating the need for complex manual role definition processes while maintaining security requirements.

Inventive Principle:
Principle #25Self-service

2Reliability

If manual role definition and access management is performed in ERP systems, then access control to enterprise resources is implemented, but delays occur in granting or denying access to systems, computer applications, or data sets

Engineering Contradiction:
Improveaccess controlVSAvoiddelays in granting or denying access
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system pre-determines authorized roles by automatically analyzing user profiles, system configurations, and enterprise resources before access requests are made. This preliminary automated role determination eliminates delays in granting or denying access, as the system can immediately evaluate access requests against pre-computed role assignments.

Inventive Principle:
Principle #10Preliminary action

3Productivity

If automated role determination using machine learning is implemented, then the time required to authorize or deny access is reduced, but the complexity of the system increases due to the need for data management models and training processes

Engineering Contradiction:
Improveresponsiveness of ERP systemVSAvoidcomplexity of data management model
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent introduces a data management model as an intermediary layer between the automated role determination process and the ERP system. This model, trained on organizational data, mediates the complex machine learning operations by providing structured inputs and outputs that integrate smoothly with existing ERP infrastructure, thereby reducing the perceived complexity while maintaining high productivity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12430452B2Systems, devices, and methods for determining and registering authorized roles
Publication Date: 2025.09.30 SAUDI ARABIAN OIL CO
  • US12430452B2 patent drawing
  • US12430452B2 patent drawing
  • US12430452B2 patent drawing

AI summary

According to an embodiment of the present disclosure, an authorized roles tool includes an analyzer to determine a type of request received from a user including an unregistered action, an unregistered permission, or a combination thereof, a predictor to predict, using a data management model, a role with which to associate the unregistered action, the unregistered permission, or the combination thereof, and a registrar to register the unregistered action, the unregistered permission, or the combination thereof to the role.