Field Control Annotations for Authorization Objects

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing application development processes are cumbersome and error-prone due to manual configuration of field control access rights in user interfaces (UIs), which complicates data retrieval and authorization management within databases.

Innovation Solution

The implementation of Data Control Language (DCL) annotations that associate authorization objects with Core Data Services (CDS) objects, enabling automatic generation of UIs based on an underlying object model and encapsulating field control data, thereby streamlining access rights management and reducing unauthorized data access requests.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual development is used to include field control access rights in the UI, then authorization control can be implemented, but the process becomes tiresome and error-prone

Engineering Contradiction:
Improveauthorization configuration accuracyVSAvoidUI development effort
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent applies preliminary action by pre-defining authorization objects and field control annotations in the CDS layer before UI generation. The field control annotations are prepared in advance with proper authorization assignments, so that when the UI is automatically generated, the authorization control is already configured correctly without requiring manual intervention during UI development.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system applies self-service by enabling automatic generation of UI field control annotations from CDS object metadata and authorization objects. The development framework automatically retrieves authorization information and generates the appropriate field control configurations without requiring manual programming, making the system configure itself.

Inventive Principle:
Principle #25Self-service

2Productivity

If automatic UI generation is implemented, then development time is reduced, but field control access rights may not be properly configured

Engineering Contradiction:
ImproveUI generation speedVSAvoidfield control authorization accuracy
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent implements feedback by establishing a metadata-driven architecture where the UI generation process continuously references and validates against the CDS object metadata and authorization objects. The system feedback loop ensures that field control annotations are generated based on the actual authorization configuration, allowing verification and correction of authorization accuracy during the automatic generation process.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent applies segmentation by separating the authorization definition (CDS objects and authorization objects) from the UI generation process. This segmentation allows the authorization layer to be independently configured and validated, then automatically translated into field control annotations during UI generation, ensuring both automation and accuracy.

Inventive Principle:
Principle #1Segmentation

3Reliability

If detailed field control annotations are manually created for each UI field, then precise authorization control is achieved, but data retrieval complexity increases

Engineering Contradiction:
Improvefield-level access control precisionVSAvoiddata retrieval structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies universality by creating a standardized field control annotation structure that serves multiple functions simultaneously. The same annotation mechanism handles both data retrieval configuration and authorization control enforcement across all UI fields. This universal approach eliminates the need for separate complex configurations for each function, simplifying the overall data retrieval structure while maintaining precise field-level access control.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10127365B2Field control annotations based on authorization objects
Publication Date: 2018.11.13 SAP SE
  • US10127365B2 patent drawing
  • US10127365B2 patent drawing
  • US10127365B2 patent drawing

AI summary

An application scaffold is generated based on an object model. The object model includes CDS objects and DCL objects. The CDS objects and the DCL objects are evaluated together with corresponding CDS annotations and DCL annotations. Based on the evaluation, a field control hub is generated. The field control hub evaluates the DCL annotations and determines, based on one or more authorization objects from the DCL annotations, field control data for a field from a number of fields of a UI. When a user requests the UI, the field of the UI is displayed in accordance with the determined field control data for a role of the user.