Metadata-Driven Restricted Measures for Secure Report Generation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In multitenant cloud-based computing environments, managing restricted measures for report generation is inefficient due to the need for users to access and filter underlying data, which can be tedious and inflexible, especially when dealing with sensitive information and varying permissions.

Innovation Solution

Implementing metadata-driven restricted measures that decouple restricted measures from database views, allowing users to manage and update them based on licensing and permissions, enabling low-code or no-code solutions for rich report generation without direct access to underlying data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If report users directly access and filter underlying database data to generate reports, then report generation flexibility is improved, but system security and permission control deteriorate

Engineering Contradiction:
Improvereport generation flexibilityVSAvoidsecurity risk from unauthorized data access
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces restricted measures as an intermediary layer between users and underlying database data. These restricted measures are pre-defined with specific permission controls and act as mediators that allow users to generate reports without directly accessing sensitive underlying data, thus maintaining security while enabling report generation flexibility

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If restricted measures are constructed from underlying data with proper permissions, then data security is improved, but the process becomes tedious and time consuming

Engineering Contradiction:
Improvedata securityVSAvoidtime to construct restricted measures
Core Design Contradiction:
Object-affected harmful factorsVSLoss of time

Solution Approach 1:

The patent implements preliminary action by pre-defining restricted measures with their filter criteria, data sources, and permission settings before users need them. This allows the system to automatically retrieve and apply these pre-configured restricted measures during report generation, eliminating the tedious manual construction process while maintaining security

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent enables copying of restricted measures between different reports and users. Once a restricted measure is defined with proper security controls, it can be reused and copied across multiple contexts without redefining it each time, significantly reducing the time required to construct secure restricted measures

Inventive Principle:
Principle #26Copying

3Reliability

If restricted measures are tightly coupled with database views, then data access control is improved, but system complexity and difficulty of maintenance increase

Engineering Contradiction:
Improvedata access controlVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the system by decoupling restricted measures from database views. Restricted measures are stored as independent metadata objects with their own structure and management mechanism, separate from the underlying database view implementation. This segmentation maintains access control reliability while reducing system complexity and improving maintainability

Inventive Principle:
Principle #1Segmentation

4Adaptability or versatility

If users need direct access to underlying data for report customization, then report customization capability is improved, but permission management complexity increases

Engineering Contradiction:
Improvereport customization capabilityVSAvoidpermission management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent makes restricted measures universal by designing them as reusable, parameterizable objects that can be applied across multiple reports and user contexts. Instead of managing individual permissions for each data access scenario, the system uses universal restricted measures with embedded permission controls, simplifying permission management while maintaining report customization capability

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12039069B2Metadata-driven restricted measures
Publication Date: 2024.07.16 SAP SE
  • US12039069B2 patent drawing
  • US12039069B2 patent drawing
  • US12039069B2 patent drawing

AI summary

A computer implemented method can receive a metadata definition of a restricted measure pertaining to a database including a plurality of database tables. The restricted measure has a label, and the metadata definition includes one or more filter criteria configured to filter values contained in the plurality of database tables. In a report designer user interface for a report, the method can present the label of the restricted measure as an option based on the metadata definition. The method can receive a selection of the label of the restricted measure in the report designer user interface. Responsive to the selection, the method can link the metadata definition of the restricted measure to the report. When generated, the report requests access to the values contained in the plurality of database tables via application of the one or more filter criteria of the metadata definition.