Role-Based Access Control for Group Communication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional access control methods in group-based communication systems are limited to static account types, such as administrators and standard users, making it difficult to manage permissions for large-scale organizations with diverse roles and requirements.

Innovation Solution

A role-based access management system that dynamically allocates customizable permissions to users based on their assigned roles within the group-based communication system, allowing for dynamic delegation of access rights.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If traditional static account types (administrator and standard user) are used for access control, then the system structure is simple and easy to implement, but the system lacks flexibility and cannot meet diverse role requirements in large-scale organizations

Engineering Contradiction:
Improvecustomization of permissionsVSAvoidaccess control system structure
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the monolithic access control system into distinct components: roles, permissions, and users. Each user can be assigned one or more roles, and each role contains a specific set of permissions. This segmentation allows organizations to create customized role structures that match their specific needs without requiring complex individual permission management for each user.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces dynamic role-based access control that allows permissions to be flexibly assigned and modified based on organizational needs. Roles can be created, modified, and assigned dynamically without reconfiguring the entire access control system. This dynamic structure enables the system to adapt to changing organizational requirements while maintaining a manageable framework.

Inventive Principle:
Principle #15Dynamics

2Measurement precision

If manual assignment of permissions on a per-user basis is implemented, then precise access control is achieved, but the management becomes infeasible for large-scale organizations

Engineering Contradiction:
Improvepermission assignment accuracyVSAvoidpermission management efficiency
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The patent introduces roles as intermediary entities between users and permissions. Instead of directly assigning permissions to users, the system assigns permissions to roles, and then assigns roles to users. This intermediary layer dramatically simplifies permission management in large-scale organizations by allowing administrators to manage permissions at the role level rather than individually for each user.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent makes roles universal containers that can hold multiple permissions and be assigned to multiple users. A single role can serve multiple functions across different users and contexts, allowing precise access control to be achieved through reusable role definitions. This universality enables efficient management of complex permission structures without requiring individual configuration for each user.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Adaptability or versatility

If a role-based access control system with customizable permissions is implemented, then flexibility and adaptability are improved, but the system complexity increases

Engineering Contradiction:
Improverole customization capabilityVSAvoidaccess control system architecture
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the access control system into distinct, manageable components: users, roles, and permissions. This segmentation allows each component to be independently configured and managed, reducing overall system complexity while maintaining high adaptability. Organizations can customize roles and permissions without affecting the underlying system architecture.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements a dynamic role-based access control system where roles and permissions can be flexibly configured and modified. The system architecture supports dynamic addition, modification, and removal of roles and permissions without requiring structural changes. This dynamic capability provides high adaptability while maintaining a consistent and manageable system framework.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS12143917B2Role-based access control system
Publication Date: 2024.11.12 SALESFORCE INC
  • US12143917B2 patent drawing
  • US12143917B2 patent drawing
  • US12143917B2 patent drawing

AI summary

A computer-readable media, system, and method for providing role-based access management to channels within a group-based communication system. Role-based access management allows for a plurality of roles to be established and for users to be associated with these roles. Roles may be associated with sets of permissions allowing users assigned to the respective role to perform various actions within the group-based communication system. The group-based communication system may include preset, system roles with predetermined permissions and custom, user-defined roles may be created by administrators within the group-based communication system.