Form Authorization via Time Property Fields
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing form-authorizing methods in management software systems, such as ERP, fail to effectively control permissions, leading to potential leakage of company information, especially when employees need to access data within specific time frames.
Innovation Solution
A form-authorizing method based on time property fields, which allows for the selection of grantees and forms, displays time property fields for setting permission time ranges. These ranges can be customized to include specific time periods, such as from a current time point, a start time, a deadline, or where a time field value is null, enhancing control over data access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If employees are authorized according to post permissions to view all historical and current data, then they can access necessary information for their work, but company information leakage occurs when employees should not view historical data or data outside their authorization scope
Solution Approach 1:
The patent segments the authorization control into multiple dimensions: time segmentation (historical data vs. current data with different access permissions), spatial segmentation (different data fields within forms), and hierarchical segmentation (department-level, role-level, and field-level permissions). This segmentation allows employees to access necessary data while preventing unauthorized access to sensitive information.
Solution Approach 2:
The patent implements dynamic authorization that automatically adjusts permission scope based on employee attributes (department, position, hire date), current time, and data timestamps. The system dynamically determines whether an employee can view historical or current data without manual intervention, adapting permissions in real-time to prevent information leakage while maintaining operational convenience.
2Object-affected harmful factors
If permission control is restricted to prevent information leakage, then information security is improved, but employees cannot efficiently access data within specific time frames for temporary transfers or reviews
Solution Approach 1:
The system performs preliminary authorization configuration by pre-defining permission rules based on employee attributes, data classification, and time parameters. When employees need to access data, the system automatically evaluates their permissions against pre-configured rules, eliminating the need for manual permission requests and approvals, thus maintaining both security and efficiency.
Solution Approach 2:
The patent implements automatic feedback mechanisms where the system continuously monitors employee attributes, current time, and data timestamps to dynamically adjust permission grants. The system provides real-time feedback on authorization status, automatically enabling or disabling access based on predefined security rules, ensuring information security without manual intervention that would reduce productivity.
3Ease of operation
If all data in a form is accessible once permission is granted, then operational simplicity is maintained, but unauthorized access to data outside the intended scope occurs
Solution Approach 1:
The patent applies local quality control by differentiating permission levels within different fields of the same form. Instead of granting uniform access to all data, the system assigns specific permission attributes to individual fields based on their sensitivity, classification, and relevance to the employee's role. This allows employees to access only the specific fields they need while preventing access to unauthorized data within the same form.
Data Source
AI summary
A form-authorizing method based on time property fields of a form is disclosed in the present invention, including: selecting one or more grantees; selecting a form, and displaying time property fields of which permission time ranges need to be set in the selected form; respectively setting a permission time range for each time property field, wherein the permission time range comprises one or more of the following six types: a time range from a time point, which is determined by going backwards from a current time for a fixed time length, to the current time, a time range from a start time to a current time, a time range from a deadline to a system initial time, a time range from a start time to a deadline, a time range where a time field value is null, and a time range from a system initial time to a current time; and after completing setting the permission time ranges, saving the settings. In the present invention, the operation permissions within a period of time in the form can be authorized to a grantee according to actual needs, thus satisfying requirements for form authorization in various time-limited cases.


