Role-Based Form Data Authorization via Segmented User Mapping
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional role-based access control methods for managing database permissions in large-scale application systems are cumbersome and prone to errors, especially during employee changes such as resignation, transfer, or induction, due to the complexity of managing roles and permissions, leading to increased workloads and potential security vulnerabilities.
Innovation Solution
An authorization method based on form data that allows for dynamic authorization by selecting specific roles and users, enabling automatic adjustment of permissions, where each role is uniquely related to a user, simplifying permission management and reducing errors by treating roles as independent entities rather than groups.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of manufacture
If role-based access control is implemented with roles representing groups/classes, then permission management becomes more organized, but operation complexity increases when user permissions need to be adjusted
Solution Approach 1:
The patent segments the relationship between roles and users by introducing a one-to-one mapping where each role is uniquely associated with a single user. This segmentation allows permission adjustments to be made at the user level without affecting other users sharing the same role, thereby resolving the operational complexity while maintaining organized permission management through the role structure.
2Productivity
If roles are treated as groups that can be assigned to multiple users, then authorization efficiency improves, but error probability increases during permission changes
Solution Approach 1:
The patent segments the role-user relationship into unique one-to-one mappings, where each role is exclusively assigned to one user. This segmentation eliminates the risk of unintended permission propagation to other users while maintaining efficient authorization through the role mechanism, thus resolving the contradiction between authorization efficiency and permission change accuracy.
3Ease of manufacture
If conventional role authorization is used where one role corresponds to multiple users, then system setup becomes simpler, but adaptability decreases when employee changes occur
Solution Approach 1:
The patent introduces dynamic adaptability by establishing a one-to-one correspondence between roles and users, allowing the system to automatically adapt to employee changes such as resignations, transfers, or promotions. When user information changes, the permission system dynamically adjusts without requiring complex reconfiguration, thereby maintaining simple system setup while significantly improving adaptability to organizational changes.
Data Source
AI summary
An authorization method based on form data gotten by a role is disclosed in the present invention, including: selecting one or more grantees; selecting a form, and displaying an authorized field used for searching form data; displaying all roles in a system, defining a role that needs to be used for searching form data as a target role, and selecting a target object for each target role respectively, where the target object is a current object, a historical object, or all objects; defining a target role and a user or an employee in its target object as a limited value; for each target role of each authorized field, respectively getting a set of form data, any limited value of the target role of which is included by a field value of the authorized field in the form, and authorizing an operation permission to the set. The present invention achieves dynamic authorization of form data, so that related permissions can be adjusted automatically in the resignation, transfer, induction of the employees and other cases, thus reducing workloads of the authorization operation and making it less error-prone.


