Dynamic Certificate Access for Secure Document Review
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In large organizations, especially in the pharmaceutical industry, the process of drafting, approving, and publishing reports is cumbersome due to the need for input from multiple departments and the requirement to safeguard sensitive data, leading to inefficiencies in data review and approval processes, particularly with the Annual Product Quality Review (APQR) reports.
Innovation Solution
A system and method for electronic document access approval that uses a user profile module and a rules management module to determine user permissions based on security scores, allowing users to access and review documents using either a generic or individual certificate, depending on the file's configuration and the user's security score, thereby streamlining the review and approval process while maintaining data security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a generic certificate is used to indicate review of data, then the ease of operation is improved and device complexity is reduced, but the reliability and security are worsened due to insufficient user identification
Solution Approach 1:
The system dynamically determines whether to use a generic certificate or an individual user certificate based on the user's security score. Users with security scores above a threshold can use the generic certificate for ease of operation, while users below the threshold must use individual certificates to ensure reliable identification and security.
2Reliability
If individual user certificates are required for all users, then the reliability and security are improved, but the ease of operation and device complexity are worsened
Solution Approach 1:
The system applies different certificate requirements to different users based on their security scores. Users with higher security scores enjoy the convenience of generic certificate usage, while users with lower security scores are required to use individual certificates, creating a differentiated access experience.
3Reliability
If multiple departments and subject matter experts review data manually, then the reliability of data review is improved, but the productivity and time required are worsened
Solution Approach 1:
The system automatically determines user permissions and certificate requirements based on stored security scores, eliminating the need for manual permission assignment and reducing the administrative overhead of coordinating multiple reviewers.
4Reliability
If security scores and user profiles are manually managed, then the reliability of access control is improved, but the device complexity and time required for management are worsened
Solution Approach 1:
The system stores security scores and user profiles in a database, creating a feedback loop where access decisions are automatically adjusted based on stored user characteristics, reducing the need for manual account management and improving consistency.
Data Source
AI summary
A method of electronic document access approval including receiving an access request from a user to electronically access data; receiving a request from the user to indicate the data within the electronic file has been reviewed; determining whether the electronic file is configured to indicate having been reviewed by the user based on a generic certificate; determining a file review threshold security score, wherein the file review threshold security score is a minimum security score to permit the use of a generic certificate by any particular user to indicate review of the data; and determining whether the user can indicate review of the data using the generic certificate based on whether the electronic file is configured to indicate having been reviewed by the user based on the generic certificate and whether the user has a user security score that is greater than the file review threshold security score.


