Form Field Authorization via Third-Party Value Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional management software systems, such as ERP, face inefficiencies in user authorization, particularly in batch operations and fine-grained control of field values, leading to potential information leakage and complex permission management in large-scale applications.
Innovation Solution
A method for authorizing form field values using third-party fields, allowing for selective viewing and modification permissions based on specific job responsibilities, by selecting grantees, forms, and third-party fields with defined options, which improves authorization efficiency and reduces errors.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional field authorization is used to allow users to view form field values, then users can access necessary information, but users can view excessive data beyond their job responsibilities causing information leakage
Solution Approach 1:
The patent segments authorization control from two dimensions: (1) field-level segmentation where each form field can be independently authorized, and (2) value-level segmentation where specific field values can be restricted. This allows precise control where user C can view contract-signing time and signer but not customer name or industry, preventing information leakage while maintaining necessary access.
Solution Approach 2:
The patent applies local quality by allowing different authorization rules for different fields and their values within the same form. For example, the contract form can have customer name restricted to specific industries while other fields remain accessible, enabling differentiated access control tailored to each field's sensitivity and user needs.
2Reliability
If individual user authorization is configured manually, then each user gets appropriate access rights, but the authorization operation has low efficiency and creates tremendous workload for systems with large numbers of users
Solution Approach 1:
The patent merges individual user authorization with role-based access control (RBAC). Instead of configuring permissions for each user separately, administrators define roles with specific field and value authorization rules, then assign multiple users to these roles. This combines the precision of individual authorization with the efficiency of batch operations, allowing thousands of users to inherit consistent authorization rules from their roles.
Solution Approach 2:
The patent makes authorization rules universal by allowing them to be defined once at the role level and applied to multiple users. A single authorization configuration for a role can serve numerous users with similar job responsibilities, eliminating repetitive manual configuration while maintaining accurate permission control across the organization.
3Adaptability or versatility
If conventional authorization allows users to view authorized field values, then users can access required data, but users cannot be restricted to specific field value conditions based on third-party fields
Solution Approach 1:
The patent introduces third-party fields as intermediaries that mediate between user roles and authorized field values. These third-party fields (such as customer industry, contract type, or regional codes) serve as conditional filters that dynamically control access to specific field values. This allows complex authorization logic to be expressed through simple field value matching without requiring complicated permission structures.
4Productivity
If batch user authorization is implemented without fine-grained control, then authorization efficiency improves, but information security decreases due to inability to restrict access to specific field values
Solution Approach 1:
The patent adds another dimension to authorization control by introducing field value-level restrictions beyond traditional field-level control. This creates a multi-dimensional authorization framework where permissions are controlled at four levels: form, field, field value, and third-party field condition. This enables batch authorization efficiency while maintaining fine-grained security control through the additional value-level dimension.
Data Source
AI summary
A method for authorizing a field value of a form field by means of a third-party field is provided. The method includes selecting one or more grantees; selecting a form to be authorized, and displaying fields which need control authorization of the permission to view field values by means of third-party fields; selecting one or more third-party fields for each field respectively, where the third-party field includes one or more options; and authorizing a viewing permission of a field value of an authorized field of form data corresponding to each option of each third-party field respectively.


