E-Business Permission Verification via Reference System Logging
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing e-business systems face challenges in identifying and configuring the precise set of permissions required for customized business processes, leading to potential over-permissioning or under-permissioning, which can hinder process execution and compromise security.
Innovation Solution
A verification method and system that uses a reference system to log and process permission checks, creating reference data for comparison with the target system, allowing for the identification and correction of permission settings to ensure accurate and secure execution of business processes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If permission settings are configured manually for customized business processes, then flexibility and adaptability are improved, but the risk of over-permissioning or under-permissioning increases, compromising security and process execution
Solution Approach 1:
The system automatically logs permission checks during business process execution and uses this feedback to verify whether configured permissions are correct. The verification process compares actual permission usage against configured permissions, providing feedback that identifies over-permissioning or under-permissioning issues without requiring manual reconfiguration.
Solution Approach 2:
The system performs self-verification by automatically logging its own permission checks and comparing them against configured permissions. This self-service approach eliminates the need for external manual auditing while maintaining high accuracy in permission configuration verification.
2Reliability
If comprehensive permission verification is implemented, then security and permission accuracy are improved, but the complexity of the system increases due to additional logging and verification mechanisms
Solution Approach 1:
The verification functionality is merged with the existing business process execution framework. Permission logging is integrated into the normal transaction flow, and verification is combined with existing system operations, eliminating the need for separate complex verification infrastructure.
Solution Approach 2:
A lightweight logging mechanism serves as an intermediary between business process execution and permission verification. This intermediary captures permission check information without disrupting the main business flow, simplifying the overall system architecture while enabling comprehensive verification.
3Measurement precision
If manual auditing of permission structures is performed, then permission accuracy can be verified, but the time and expertise required increase significantly
Solution Approach 1:
The system automatically performs verification by logging its own permission checks and comparing them against configured permissions. This eliminates the need for manual auditing operations, reducing verification time from hours or days to automatic near-real-time checks without sacrificing accuracy.
Solution Approach 2:
The system continuously provides feedback on permission configuration accuracy through automatic logging and verification. This ongoing feedback mechanism replaces periodic manual audits, maintaining high measurement precision while dramatically reducing the time and expertise requirements.
4Reliability
If excessive permissions are granted to ensure process execution, then process reliability is improved, but security is compromised due to over-permissioning
Solution Approach 1:
The system logs actual permission usage during business process execution and provides feedback to identify over-permissioning. This feedback enables precise adjustment of permissions to match actual needs, maintaining process execution reliability while eliminating unnecessary security risks associated with excessive permissions.
Solution Approach 2:
The system dynamically adjusts permission parameters based on verified actual usage patterns. By changing permission parameters from static over-permissioning to dynamic verification-based configuration, the system maintains process reliability while reducing security risks through precise permission control.
Data Source
AI summary
A verification method includes configuring a reference system, running on a computer, to have the same set of executables and customizations as an e-business system to be verified. The reference system is configured with one or more roles that have permissions to execute all transactions in a scope of a planned verification. One or more business processes that are implemented in the e-business system and are in the scope of the planned verification are mapped and are executed using the reference system. Logs of permission checks conducted in the business processes are saved in a repository. Reference data is created by merging records from the logs of the permission checks with respect to at least one role in the scope of the verification. Permission settings for the at least one role in the e-business system are compared with corresponding permission values in the reference data for the at least one role. Based on comparing the permission settings, an indication is displayed to a user of whether the permission settings match the corresponding permission values.


