Dynamic Metadata API for Granular Database Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Content management systems face challenges in providing accurate data access control and dynamic security, as existing static metadata APIs are inadequate to describe record properties based on user permissions and object states, leading to complexities in application development and user experience.

Innovation Solution

A user programmatic interface is introduced to support dynamic security models by providing record property objects and query describe objects, which dynamically define user actions and metadata, enabling granular access control and accurate representation of data records based on user permissions and object states.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If static metadata APIs are used to describe record properties, then the system structure is simple, but the system cannot accurately represent dynamic security and user permissions

Engineering Contradiction:
Improveaccuracy of record property descriptionVSAvoidcomplexity of metadata API
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent transforms static metadata APIs into dynamic metadata APIs that adapt to user permissions and object states. The metadata is no longer fixed but changes based on the user's role, permissions, and the state of the data object, enabling accurate representation of dynamic security requirements while maintaining a unified API interface.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the parameters of the metadata API from static values to dynamic values that depend on user permissions and object states. The metadata now includes parameters such as user role, permission level, and object state, which dynamically adjust the description of record properties to reflect the current security context.

Inventive Principle:
Principle #35Parameter changes

2Ease of operation

If dynamic security models are implemented with granular access control, then user experience is improved, but application development complexity increases

Engineering Contradiction:
Improveuser experience qualityVSAvoidapplication development complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent implements a self-service mechanism where the dynamic metadata API automatically provides the necessary security and permission information to applications. The system itself generates and manages the dynamic metadata based on user permissions and object states, eliminating the need for developers to manually implement complex security logic and reducing development complexity.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent introduces feedback mechanisms where the system continuously monitors user permissions and object states and updates the metadata accordingly. This feedback loop ensures that the metadata always reflects the current security context, enabling applications to automatically adapt to dynamic security requirements without manual intervention.

Inventive Principle:
Principle #23Feedback

3Adaptability or versatility

If static metadata is used to describe record properties, then the system is easy to implement, but it cannot support dynamic user permissions and object states

Engineering Contradiction:
Improvesupport for dynamic securityVSAvoidease of system implementation
Core Design Contradiction:
Adaptability or versatilityVSEase of manufacture

Solution Approach 1:

The patent creates a universal metadata API that serves multiple functions: it describes record properties, user permissions, object states, and security constraints all in one unified interface. This multi-functional metadata system replaces the need for separate static metadata and security configuration systems, making the system more adaptable while maintaining ease of implementation through a single standardized API.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11222133B1User programmatic interface for supporting data access control in a database system
Publication Date: 2022.01.11 VEEVA SYSTEMS INC
  • US11222133B1 patent drawing
  • US11222133B1 patent drawing
  • US11222133B1 patent drawing

AI summary

Systems and methods for providing an API for a database system. The API may be provided to enable external application developers to build applications that can support the dynamic security model of the content management system and describe the runtime properties of records in data objects. The API of may provide a record property object and/or a query describe object when returning data set in response to a query by providing information about actions an end user can take on the data records, and to provide metadata required to understand a data response.