Time-Range Mailbox Access Control for Data Leakage Prevention

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional methods for authorizing permissions in management software systems, such as ERP, fail to effectively control access to mailbox and instant messaging content, leading to information leakage and operational inefficiencies, particularly during employee transfers or changes in roles.

Innovation Solution

A method for setting operation time ranges for mailbox and instant messaging content, allowing access only within specified permission times, which can be based on a fixed duration backward from the current time, from a start time to the current time, from a deadline to the system initial time, or from a start time to a deadline, thereby controlling access dynamically.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional authorization methods are used to allow employees to view all historical and current data in mailbox and instant messaging accounts, then employees can access complete information for their roles, but information leakage occurs and data security is compromised

Engineering Contradiction:
Improvedata securityVSAvoidinformation leakage
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent implements dynamic permission control by introducing time-range-based authorization. Instead of static all-or-nothing access, the system dynamically adjusts what data employees can view based on their role, the current time, and predefined time ranges. This allows the system to automatically grant access to historical data only within appropriate time windows, preventing both information leakage and ensuring data security simultaneously.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the authorization parameter from binary (authorized/not authorized) to temporal (authorized within specific time ranges). By parameterizing access control with time ranges, the system can precisely control when employees can view historical data, transforming a security vulnerability into a controlled access mechanism that maintains both security and reliability.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If manual re-authorization is performed when employees are transferred or change roles, then permission control can be adjusted, but work efficiency decreases and operational delays occur

Engineering Contradiction:
Improvepermission control accuracyVSAvoidwork efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies preliminary action by pre-configuring time-range-based permission rules for different roles and data types. When employees are transferred or change roles, the system automatically applies the appropriate pre-defined time range permissions based on their new role, eliminating the need for manual re-authorization and ensuring accurate permission control without operational delays.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements self-service authorization by automatically adjusting employee permissions based on their role and the current time against predefined rules. When an employee's role changes, the system autonomously recalculates and applies the appropriate time-range permissions without requiring manual intervention, maintaining both accuracy and efficiency.

Inventive Principle:
Principle #25Self-service

3Ease of operation

If employees are authorized to view all data in mailbox accounts during temporary transfers for review, then review access is granted, but unauthorized access to unrelated data occurs causing data leakage

Engineering Contradiction:
Improvereview access convenienceVSAvoiddata security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent applies local quality by granting review access selectively to specific time ranges and data types rather than universally. When employees are temporarily transferred for review purposes, the system configures permissions that allow access only to data within specific time ranges relevant to their review task, preventing unauthorized access to unrelated data while maintaining review convenience.

Inventive Principle:
Principle #3Local quality

4Reliability

If mailbox accounts are manually re-related to employees after transfers, then account assignments are updated, but work interruptions occur and operational efficiency decreases

Engineering Contradiction:
Improveaccount-employee matching accuracyVSAvoidre-authorization time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies preliminary action by pre-configuring time-range-based permission rules that automatically apply when employees are transferred. Instead of manually re-relating mailbox accounts to employees, the system automatically applies the appropriate time-range permissions based on the employee's new role and current time, eliminating re-authorization delays while ensuring accurate account-employee matching.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11563746B2Method for configuring operating time period for mailbox content and instant messaging content in system
Publication Date: 2023.01.24 CHENGDU QIANNIUCAO INFORMATION TECH CO LTD
  • US11563746B2 patent drawing
  • US11563746B2 patent drawing

AI summary

A method for setting an operation time range of mailbox content and instant messaging content in a system is disclosed in the present invention, wherein a method for setting an operation time of mailbox content includes: selecting a role, a user or an employee as a mailbox user; setting a permission time range for each mailbox user, wherein said permission time range includes one or more of the following types: a time range from a time point, which is determined by going backwards from a current time for a fixed time length, to the current time, a time range from a start time to a current time, a time range from a deadline to a system initial time, and a time range from a start time to a deadline; and the content within the permission time range of the mailbox user in a mailbox account used by the mailbox user being operated by said mailbox user. In the present invention, by setting a permission time range, only the content set within the permission time range in the mailbox account or the instant messaging account can be operated, thus improving the security of data information in the mailbox account and the instant messaging account.