ERP Module Usage Tracking for Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The complexity of managing and securing enterprise resource planning (ERP) systems in large organizations is exacerbated by the decentralized structure, where local administrators may be unaware of other systems and users, leading to potential security vulnerabilities and inefficient data management due to unused modules and unauthorized access.

Innovation Solution

A data collection system identifies and records module usage across ERP systems, generating reports to manage and restrict access, and an access control system prevents unauthorized access by setting attributes and limiting user views to authorized components, integrating data with organizational charts for intuitive management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If decentralized ERP systems are implemented to allow local administrators to manage their own systems, then ease of operation and local autonomy are improved, but system complexity and security management difficulty increase

Engineering Contradiction:
Improvelocal system managementVSAvoidoverall system management
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent implements a central administrator as an intermediary who maintains a comprehensive database of all ERP systems, modules, and users across the organization. This central administrator mediates between local administrators' autonomy and organizational-wide security requirements, resolving the contradiction by providing centralized oversight without eliminating local management capabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates a universal access control system that operates across all decentralized ERP systems. The central administrator uses a single comprehensive interface to manage security policies, user access, and module availability across multiple systems, making the management process universal rather than system-specific.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Ease of operation

If local administrators manage only their local system users, then ease of operation is improved, but security vulnerability detection capability deteriorates

Engineering Contradiction:
Improvelocal user managementVSAvoidsecurity vulnerability assessment
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The central administrator acts as an intermediary who aggregates security information from all local systems and performs comprehensive security assessments. This intermediary role enables organization-wide security monitoring while preserving local administrators' operational simplicity in managing their own users.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements a feedback mechanism where the central administrator receives information about all users and systems, performs security assessments, and communicates findings back to relevant local administrators. This feedback loop improves security vulnerability detection while maintaining local management autonomy.

Inventive Principle:
Principle #23Feedback

3Adaptability or versatility

If all ERP modules are installed and active in each system, then adaptability and functionality are improved, but data management complexity and unauthorized access risks increase

Engineering Contradiction:
Improvemodule functionalityVSAvoiddata management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent applies local quality by allowing each ERP system to have different module configurations based on local needs. The central administrator database tracks which modules are active in each system, enabling tailored functionality while simplifying data management through centralized awareness of the actual module distribution across the organization.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS8260812B2System management by component usage switches
Publication Date: 2012.09.04 SAP SE
  • US8260812B2 patent drawing
  • US8260812B2 patent drawing
  • US8260812B2 patent drawing

AI summary

Systems and methods for managing multiple systems in an enterprise resource planning system are provided. In an embodiment, data identifying modules and entities using modules or systems may be collected from each system in enterprise resource planning system. The collected data may then be organized to show a usage landscape of entire enterprise resource planning system. In an embodiment, the collected data may also be merged with other organizational data, such as organizational chart data, to present the usage landscape in an intuitive manner using the organizational structure data from the organizational chart. The collected data may also be used to identify potential data inconsistencies across different systems or may be used to limit connectivity to only authorized systems or modules. In some embodiments, attributes such as attributes identifying modules and entities may be inputted into a system which then distributes the attributes to other systems.