Incident Access Control for Supply Chain Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current supply chain management systems lack efficient mechanisms for providing selective access to third-party users for individual incidents, leading to potential data security breaches and unnecessary access to irrelevant information.
Innovation Solution
The system implements a method for granting selective access to external users and non-users by associating them with specific incidents, using access links and visibility groups with different access permissions, and allowing administrators to manage and revoke access permissions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If third-party users are added as users under the account owning the incident, then they can access the incident data, but they may retain access to information they should not have and require ongoing management
Solution Approach 1:
The system segments access permissions by creating distinct user types (internal users, external users, and non-users) and associating them with specific incidents rather than granting blanket account access. This segmentation allows precise control over which incidents each user type can view, eliminating unnecessary access while maintaining operational ease.
Solution Approach 2:
The patent implements local quality by allowing different visibility permissions for different incidents within the same account. External users and non-users can be granted access to specific incidents based on their role and needs, while maintaining no access to other incidents. This incident-level granularity ensures data security while enabling necessary collaboration.
2Reliability
If selective access to individual incidents is implemented, then data security is enhanced, but system complexity increases
Solution Approach 1:
The system achieves universality by creating a multi-functional access control framework that handles internal users, external users, and non-users through a unified incident-association mechanism. This single framework provides diverse access levels (account-level for internal users, incident-level for external users and non-users) without requiring separate complex systems, thus enhancing security while managing complexity.
Solution Approach 2:
The patent introduces an intermediary mechanism where the supply chain incident management system itself acts as the mediator between users and incident data. Rather than relying on traditional account-based access controls, the system uses incident-level associations as an intermediary layer that automatically enforces security rules, simplifying the access control logic while maintaining high security standards.
3Adaptability or versatility
If external users are granted access to all records in a secure system, then collaboration is enabled, but unauthorized access to sensitive information becomes a risk
Solution Approach 1:
The system implements dynamics by making access permissions incident-specific and time-bound for external users and non-users. Rather than static account-level permissions, the system dynamically grants access only to relevant incidents and automatically revokes it when the incident is resolved or the user is removed, enabling collaboration while minimizing unauthorized access risk.
Solution Approach 2:
The patent applies discarding and recovering by automatically revoking (discarding) access permissions for external users and non-users when they are no longer needed for a specific incident. The system recovers control by returning the incident to its original security state, ensuring that sensitive information is protected from unauthorized access while maintaining collaboration capability during the incident lifecycle.
Data Source
AI summary
Data records associated with an account may be used to track incidents in a supply chain. Incident records associated with a supply chain are accessible and modifiable by users with an active user account associated with an incident management application. The application may receive requests to perform user actions on multiple incidents. Each request may be validated according to account-specific permissions and user-specific privileges. Multiple users may be grouped according to user classes indicative of their status as internal users or external users. Non-users may be invited to perform user actions on incident data through access links generated by the application instance. Access links may allow a non-user to become an invited or registered external user. A registered external user may be promoted to a named external user. Various visibility groups may limit the user actions that any given user of a particular user class can perform on incident data.


