Permission Comparator for Database Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Managing complex access controls and permissions in database systems becomes time-consuming and intricate as users have multiple profiles and permission sets, making it difficult to compare and synchronize permissions efficiently.

Innovation Solution

A permission management system that compares users, profiles, and permission sets to identify similarities and differences, allowing administrators to assign permissions and generate new sets, thereby simplifying the management of permissions and reducing the complexity of access control.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If multiple permission sets are assigned to users, then access control flexibility is improved, but permission management complexity increases

Engineering Contradiction:
Improveaccess control flexibilityVSAvoidpermission management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments permission management by introducing permission sets as independent, reusable units that can be assigned to multiple users. Each permission set contains specific permissions (e.g., object permissions, app permissions, field permissions) that can be independently configured and then assigned to any number of users, dividing the complex permission management task into manageable segments.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent enables copying of permission sets between users. Once a permission set is configured for one user, it can be copied and assigned to other users with similar requirements, eliminating the need to manually configure the same permissions repeatedly and reducing management complexity while maintaining flexibility.

Inventive Principle:
Principle #26Copying

2Measurement precision

If permission comparison is performed manually, then accuracy is improved, but time consumption increases

Engineering Contradiction:
Improvepermission comparison accuracyVSAvoidtime consumption
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent implements automatic permission comparison functionality that allows the system to self-evaluate permission differences between users without manual intervention. The system automatically identifies common permissions, unique permissions, and missing permissions by comparing permission sets, providing accurate results while eliminating the time-consuming manual comparison process.

Inventive Principle:
Principle #25Self-service

3Stability of the object's composition

If permissions are synchronized across users, then consistency is improved, but system operation complexity increases

Engineering Contradiction:
Improvepermission consistencyVSAvoidsystem operation complexity
Core Design Contradiction:
Stability of the object's compositionVSEase of operation

Solution Approach 1:

The patent simplifies permission synchronization by enabling administrators to copy permission sets from one user to another with a single operation. This copying mechanism ensures consistent permission configurations across multiple users while maintaining ease of operation, as the system handles the complex synchronization process automatically through the copy function.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS10296753B2Permission comparator
Publication Date: 2019.05.21 SALESFORCE INC
  • US10296753B2 patent drawing
  • US10296753B2 patent drawing
  • US10296753B2 patent drawing

AI summary

A permission management system enables a system administrator to more effectively manage the large number of permissions associated with database systems. The permission management system accumulates groups of permissions associated with selected users, profiles, or permission sets. The permission management system then performs selectable comparisons on the different groups of permissions, such as identifying common permissions, unique permissions, and differing permissions. The permission management system also may identify permissions in a first permission group that do not exist in a second permission group and assign the identified permissions to the second permission group.