Role-Nature Email Account Allocation for Permission Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing email management methods face challenges such as information leakage, cumbersome permission management, and inefficient email account allocation due to the conventional role-based access control mechanism, where roles are groups and not individual entities, leading to difficulties in managing permissions and email account transitions during employee changes, transfers, and resignations.
Innovation Solution
A method where a role-nature email account is allocated to each role based on its work content, allowing only one role to be related to one email account, and one user can be related to multiple roles, enabling efficient email account management by ensuring that email accounts are not shared among unrelated users and simplifying permission management by treating roles as independent entities.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If conventional role-based access control is used where roles are groups corresponding to multiple users, then permission management can be simplified, but email account allocation becomes cumbersome and information leakage risks increase
Solution Approach 1:
The patent segments the traditional group-based role into individual user-specific roles. Each user has their own role instance with unique email account allocation, separating the role definition from role instantiation. This allows permission templates to be reused across users while maintaining distinct email account assignments for each user, resolving the conflict between simplified permission management and complex email allocation.
Solution Approach 2:
The patent introduces a role template as an intermediary between permission definitions and user assignments. The template defines the permission structure, while actual role instances for each user inherit from this template but maintain independent email account bindings. This intermediary layer enables centralized permission management while allowing individualized email account allocation.
2Adaptability or versatility
If roles are defined as groups that can be assigned to multiple users, then permission reuse is improved, but email account transitions during employee changes become difficult to manage
Solution Approach 1:
The patent divides the role concept into two independent components: role template (defining permissions) and role instance (defining user-specific bindings including email accounts). When permissions need to be reused, the template is copied or referenced. When email accounts need to transition, only the role instance for the specific user is modified, leaving other user instances unchanged. This segmentation resolves the conflict between permission reuse and email account transition management.
Solution Approach 2:
The patent applies local quality by allowing different properties of the role to have different inheritance behaviors. Permission-related properties are inherited from the template for reuse, while email account binding properties are locally customized for each user instance. This enables selective inheritance where permissions are shared but email accounts remain user-specific and easily transferable.
3Device complexity
If one role corresponds to multiple users, then the number of roles needed is reduced, but the risk of information leakage when users leave or transfer increases
Solution Approach 1:
The patent segments the shared role into multiple user-specific role instances that reference a common permission template. Each user instance has its own email account binding, so when a user leaves or transfers, only their specific role instance needs to be deactivated or reassigned. This prevents other users' email accounts and information from being affected, thereby maintaining information security while keeping the overall role structure manageable.
Solution Approach 2:
The patent uses copying of role templates to create user-specific role instances. Each instance is a copy that inherits permission definitions but maintains independent email account bindings. This copying mechanism allows efficient role creation and reuse while ensuring that each user has an isolated email account association, preventing cross-user information leakage during personnel changes.
4Adaptability or versatility
If permission changes are made for individual users in a group-based role system, then user-specific customization is achieved, but the entire role's permissions must be changed affecting all users
Solution Approach 1:
The patent segments permission management into template-level operations and instance-level operations. At the template level, permission definitions are created and reused. At the instance level, each user's role instance can have independent email account bindings and can be individually activated or deactivated. This allows user-specific customization without affecting other users while maintaining high efficiency through template reuse.
Solution Approach 2:
The patent introduces dynamic role instances that can be independently configured for each user while referencing a static permission template. The role instances are dynamic in that they can be created, modified, or deactivated independently for each user, whereas the template remains stable. This dynamic instantiation allows flexible user-specific customization without requiring changes to the shared permission structure, maintaining both adaptability and productivity.
Data Source
AI summary
A method for a user/an employee in a system to acquire an email account is disclosed in the present invention, including: relating a role-nature email account to a role according to work content of the role in the system, wherein during the same period, one role can only be related to one role-nature email account, and one role-nature email account can only be related to one role; said role is an independent individual not a group/a class, and during the same period, one role can only be related to a unique user, while one user is related to one or more roles; and creating a relation between a user and a role, wherein for any user, a role-nature email accounts related to all roles related to said user are used as role-nature email accounts of the user and/or an employee corresponding to the user. According to the present invention, a corresponding role-nature email account is allocated to an employee while a post is allocated to the employee, such that it is unnecessary to allocate the role-nature email account to the employee separately, thereby reducing the workload of email account allocation.


