Metadata-Driven Restricted Measures for Secure Report Generation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In multitenant cloud-based computing environments, managing restricted measures for report generation is inefficient due to the need for users to access and filter underlying data, which can be tedious and inflexible, especially when dealing with sensitive information and varying permissions.
Innovation Solution
Implementing metadata-driven restricted measures that decouple restricted measures from database views, allowing users to manage and update them based on licensing and permissions, enabling low-code or no-code solutions for rich report generation without direct access to underlying data.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If report users directly access and filter underlying database data to generate reports, then report generation flexibility is improved, but system security and permission control deteriorate
Solution Approach 1:
The patent introduces restricted measures as an intermediary layer between users and underlying database data. These restricted measures are pre-defined with specific permission controls and act as mediators that allow users to generate reports without directly accessing sensitive underlying data, thus maintaining security while enabling report generation flexibility
2Object-affected harmful factors
If restricted measures are constructed from underlying data with proper permissions, then data security is improved, but the process becomes tedious and time consuming
Solution Approach 1:
The patent implements preliminary action by pre-defining restricted measures with their filter criteria, data sources, and permission settings before users need them. This allows the system to automatically retrieve and apply these pre-configured restricted measures during report generation, eliminating the tedious manual construction process while maintaining security
Solution Approach 2:
The patent enables copying of restricted measures between different reports and users. Once a restricted measure is defined with proper security controls, it can be reused and copied across multiple contexts without redefining it each time, significantly reducing the time required to construct secure restricted measures
3Reliability
If restricted measures are tightly coupled with database views, then data access control is improved, but system complexity and difficulty of maintenance increase
Solution Approach 1:
The patent segments the system by decoupling restricted measures from database views. Restricted measures are stored as independent metadata objects with their own structure and management mechanism, separate from the underlying database view implementation. This segmentation maintains access control reliability while reducing system complexity and improving maintainability
4Adaptability or versatility
If users need direct access to underlying data for report customization, then report customization capability is improved, but permission management complexity increases
Solution Approach 1:
The patent makes restricted measures universal by designing them as reusable, parameterizable objects that can be applied across multiple reports and user contexts. Instead of managing individual permissions for each data access scenario, the system uses universal restricted measures with embedded permission controls, simplifying permission management while maintaining report customization capability
Data Source
AI summary
A computer implemented method can receive a metadata definition of a restricted measure pertaining to a database including a plurality of database tables. The restricted measure has a label, and the metadata definition includes one or more filter criteria configured to filter values contained in the plurality of database tables. In a report designer user interface for a report, the method can present the label of the restricted measure as an option based on the metadata definition. The method can receive a selection of the label of the restricted measure in the report designer user interface. Responsive to the selection, the method can link the metadata definition of the restricted measure to the report. When generated, the report requests access to the values contained in the plurality of database tables via application of the one or more filter criteria of the metadata definition.


