Role-Based Form Data Authorization via Segmented User Mapping

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional role-based access control methods for managing database permissions in large-scale application systems are cumbersome and prone to errors, especially during employee changes such as resignation, transfer, or induction, due to the complexity of managing roles and permissions, leading to increased workloads and potential security vulnerabilities.

Innovation Solution

An authorization method based on form data that allows for dynamic authorization by selecting specific roles and users, enabling automatic adjustment of permissions, where each role is uniquely related to a user, simplifying permission management and reducing errors by treating roles as independent entities rather than groups.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of manufacture

If role-based access control is implemented with roles representing groups/classes, then permission management becomes more organized, but operation complexity increases when user permissions need to be adjusted

Engineering Contradiction:
Improvepermission management organizationVSAvoidpermission adjustment operation
Core Design Contradiction:
Ease of manufactureVSEase of operation

Solution Approach 1:

The patent segments the relationship between roles and users by introducing a one-to-one mapping where each role is uniquely associated with a single user. This segmentation allows permission adjustments to be made at the user level without affecting other users sharing the same role, thereby resolving the operational complexity while maintaining organized permission management through the role structure.

Inventive Principle:
Principle #1Segmentation

2Productivity

If roles are treated as groups that can be assigned to multiple users, then authorization efficiency improves, but error probability increases during permission changes

Engineering Contradiction:
Improveauthorization efficiencyVSAvoidpermission change accuracy
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent segments the role-user relationship into unique one-to-one mappings, where each role is exclusively assigned to one user. This segmentation eliminates the risk of unintended permission propagation to other users while maintaining efficient authorization through the role mechanism, thus resolving the contradiction between authorization efficiency and permission change accuracy.

Inventive Principle:
Principle #1Segmentation

3Ease of manufacture

If conventional role authorization is used where one role corresponds to multiple users, then system setup becomes simpler, but adaptability decreases when employee changes occur

Engineering Contradiction:
Improvesystem setup simplicityVSAvoidemployee change adaptability
Core Design Contradiction:
Ease of manufactureVSAdaptability or versatility

Solution Approach 1:

The patent introduces dynamic adaptability by establishing a one-to-one correspondence between roles and users, allowing the system to automatically adapt to employee changes such as resignations, transfers, or promotions. When user information changes, the permission system dynamically adjusts without requiring complex reconfiguration, thereby maintaining simple system setup while significantly improving adaptability to organizational changes.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS11586758B2Authorization method for form data acquired based on role
Publication Date: 2023.02.21 CHENGDU QIANNIUCAO INFORMATION TECH CO LTD
  • US11586758B2 patent drawing
  • US11586758B2 patent drawing
  • US11586758B2 patent drawing

AI summary

An authorization method based on form data gotten by a role is disclosed in the present invention, including: selecting one or more grantees; selecting a form, and displaying an authorized field used for searching form data; displaying all roles in a system, defining a role that needs to be used for searching form data as a target role, and selecting a target object for each target role respectively, where the target object is a current object, a historical object, or all objects; defining a target role and a user or an employee in its target object as a limited value; for each target role of each authorized field, respectively getting a set of form data, any limited value of the target role of which is included by a field value of the authorized field in the form, and authorizing an operation permission to the set. The present invention achieves dynamic authorization of form data, so that related permissions can be adjusted automatically in the resignation, transfer, induction of the employees and other cases, thus reducing workloads of the authorization operation and making it less error-prone.