Role-Based Access Control for Business Transaction Data
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing on-line document collaboration systems lack the ability to securely manage and share system usage data among multiple parties involved in business transactions, as access to this sensitive information is typically restricted to the seller who set up the data room, while all parties should have full document access.
Innovation Solution
Implementing a method where specified monitors, potentially administrators or approved parties, can access and manage system usage data based on user identity, allowing for controlled access and authorization of user activities, while ensuring confidentiality and limiting data retention.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of information
If full system usage data access is provided to all parties, then transparency and due diligence management are improved, but confidentiality and security of sensitive user information deteriorate
Solution Approach 1:
The patent applies local quality by providing different access rights to different parties based on their role and authorization status. Administrators receive comprehensive system usage data access for monitoring and management purposes, while regular users only access their own usage data. This differentiated access control resolves the contradiction by ensuring transparency where needed (administrative oversight) while protecting confidentiality where required (user privacy).
Solution Approach 2:
The patent segments system usage data into different categories and provides access to different parties based on segmentation. Sensitive information such as other users' access patterns, document review history, and system metadata are separated from general document content. This segmentation allows transparent access to non-sensitive data while protecting sensitive components, resolving the transparency-confidentiality contradiction.
2Ease of operation
If system usage data is collected and made available, then due diligence management capability is improved, but exposure of confidential information in litigation increases
Solution Approach 1:
The patent introduces an intermediary layer (the administrator) who acts as a mediator between the system usage data and the parties. The administrator collects and manages usage data according to authorization rules, providing due diligence management capabilities while filtering out confidential information before presentation to users. This intermediary function resolves the contradiction by enabling management transparency while protecting against litigation risks.
3Object-affected harmful factors
If only the seller has access to system usage data, then confidentiality is maintained, but ability to manage due diligence process deteriorates
Solution Approach 1:
The patent applies dynamics by making data access rights flexible and changeable based on user roles and authorization status. Rather than static access control, the system dynamically adjusts who can access what usage data based on their position in the transaction process. Administrators gain broader access for management purposes while maintaining confidentiality protections, resolving the contradiction between confidentiality and management efficiency.
Data Source
AI summary
A method, and computer-readable media for performing the method, for managing business transactions. Electronic transaction documents are received from authenticated users and stored in a database, with system usage data regarding users' access to and use of the system captured and stored in the database. Only specified parties are afforded access to system usage data for each user.


