Time-Range Mailbox Access Control for Data Leakage Prevention
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional methods for authorizing permissions in management software systems, such as ERP, fail to effectively control access to mailbox and instant messaging content, leading to information leakage and operational inefficiencies, particularly during employee transfers or changes in roles.
Innovation Solution
A method for setting operation time ranges for mailbox and instant messaging content, allowing access only within specified permission times, which can be based on a fixed duration backward from the current time, from a start time to the current time, from a deadline to the system initial time, or from a start time to a deadline, thereby controlling access dynamically.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional authorization methods are used to allow employees to view all historical and current data in mailbox and instant messaging accounts, then employees can access complete information for their roles, but information leakage occurs and data security is compromised
Solution Approach 1:
The patent implements dynamic permission control by introducing time-range-based authorization. Instead of static all-or-nothing access, the system dynamically adjusts what data employees can view based on their role, the current time, and predefined time ranges. This allows the system to automatically grant access to historical data only within appropriate time windows, preventing both information leakage and ensuring data security simultaneously.
Solution Approach 2:
The patent changes the authorization parameter from binary (authorized/not authorized) to temporal (authorized within specific time ranges). By parameterizing access control with time ranges, the system can precisely control when employees can view historical data, transforming a security vulnerability into a controlled access mechanism that maintains both security and reliability.
2Reliability
If manual re-authorization is performed when employees are transferred or change roles, then permission control can be adjusted, but work efficiency decreases and operational delays occur
Solution Approach 1:
The patent applies preliminary action by pre-configuring time-range-based permission rules for different roles and data types. When employees are transferred or change roles, the system automatically applies the appropriate pre-defined time range permissions based on their new role, eliminating the need for manual re-authorization and ensuring accurate permission control without operational delays.
Solution Approach 2:
The system implements self-service authorization by automatically adjusting employee permissions based on their role and the current time against predefined rules. When an employee's role changes, the system autonomously recalculates and applies the appropriate time-range permissions without requiring manual intervention, maintaining both accuracy and efficiency.
3Ease of operation
If employees are authorized to view all data in mailbox accounts during temporary transfers for review, then review access is granted, but unauthorized access to unrelated data occurs causing data leakage
Solution Approach 1:
The patent applies local quality by granting review access selectively to specific time ranges and data types rather than universally. When employees are temporarily transferred for review purposes, the system configures permissions that allow access only to data within specific time ranges relevant to their review task, preventing unauthorized access to unrelated data while maintaining review convenience.
4Reliability
If mailbox accounts are manually re-related to employees after transfers, then account assignments are updated, but work interruptions occur and operational efficiency decreases
Solution Approach 1:
The patent applies preliminary action by pre-configuring time-range-based permission rules that automatically apply when employees are transferred. Instead of manually re-relating mailbox accounts to employees, the system automatically applies the appropriate time-range permissions based on the employee's new role and current time, eliminating re-authorization delays while ensuring accurate account-employee matching.
Data Source
AI summary
A method for setting an operation time range of mailbox content and instant messaging content in a system is disclosed in the present invention, wherein a method for setting an operation time of mailbox content includes: selecting a role, a user or an employee as a mailbox user; setting a permission time range for each mailbox user, wherein said permission time range includes one or more of the following types: a time range from a time point, which is determined by going backwards from a current time for a fixed time length, to the current time, a time range from a start time to a current time, a time range from a deadline to a system initial time, and a time range from a start time to a deadline; and the content within the permission time range of the mailbox user in a mailbox account used by the mailbox user being operated by said mailbox user. In the present invention, by setting a permission time range, only the content set within the permission time range in the mailbox account or the instant messaging account can be operated, thus improving the security of data information in the mailbox account and the instant messaging account.

