Security Management System for Cross-Role Modification Approval

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security management systems face difficulties in allowing users to perform tasks that span multiple security roles and geographical locations, as users must identify and coordinate with various stakeholders to obtain necessary permissions and agree on changes, which is logistically challenging, especially when stakeholders are geographically dispersed.

Innovation Solution

A method that defines areas of ownership for users, allowing them to initiate modifications and submit them to a change repository, where stakeholders review and approve the changes, granting permission for implementation only after all necessary approvals are received, enabling users to manage tasks across multiple areas despite initial permission limitations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If users are granted broad permissions to perform tasks across multiple security roles, then task completion capability is improved, but security risk increases

Engineering Contradiction:
Improvetask completion capabilityVSAvoidsecurity risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary actions by requiring users to define modification proposals and obtain stakeholder approvals before actual implementation. The change repository stores proposed modifications in advance, and the system automatically identifies and notifies relevant stakeholders before changes are applied, preventing unauthorized or unsafe modifications.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system introduces an intermediary mechanism - the change repository and automated approval workflow - between users and direct system modifications. This intermediary layer ensures that all modifications go through proper review and approval processes, maintaining security while enabling cross-role task completion.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If users must coordinate with multiple stakeholders for permission changes, then security control is improved, but operational complexity increases

Engineering Contradiction:
Improvesecurity controlVSAvoidoperational complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system enables self-service by automatically identifying stakeholders based on the modification proposal and their areas of ownership. Users don't need to manually find and contact each stakeholder; the system handles notification and tracking automatically, reducing operational complexity while maintaining security controls.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system implements feedback mechanisms by automatically notifying stakeholders of proposed modifications and tracking their approval status. The change repository maintains records of all proposals and approvals, providing transparent feedback to users about the status of their modification requests without requiring manual coordination.

Inventive Principle:
Principle #23Feedback

3Manufacturing precision

If stakeholders are required to review and approve modifications, then modification accuracy is improved, but processing time increases

Engineering Contradiction:
Improvemodification accuracyVSAvoidprocessing time
Core Design Contradiction:
Manufacturing precisionVSLoss of time

Solution Approach 1:

Stakeholders perform reviews in advance before modifications are implemented. The system allows stakeholders to review proposed modifications at their convenience and provide approvals beforehand, preventing delays during actual implementation. Changes are only applied after all necessary approvals are obtained.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system replaces manual coordination and tracking mechanisms with automated electronic workflows. The change repository and notification system automatically manage the approval process, reducing the time required for stakeholder coordination while maintaining thorough review processes.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

4Measurement precision

If users must identify and communicate with each individual for permission changes, then permission accuracy is improved, but coordination difficulty increases

Engineering Contradiction:
Improvepermission accuracyVSAvoidcoordination difficulty
Core Design Contradiction:
Measurement precisionVSEase of operation

Solution Approach 1:

The system performs self-service by automatically identifying which stakeholders are relevant to each modification proposal based on predefined areas of ownership and responsibility. Users simply submit their modification proposals, and the system handles the identification and notification of appropriate stakeholders, eliminating manual coordination while maintaining permission accuracy.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system provides universal functionality by implementing a standardized change management process that works for all types of modifications across all security roles. The change repository and automated stakeholder identification system handle diverse modification scenarios through a single unified process, improving ease of operation while maintaining precision.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS7383568B1Security management administration system and method
Publication Date: 2008.06.03 GEN DIGITAL INC
  • US7383568B1 patent drawing
  • US7383568B1 patent drawing
  • US7383568B1 patent drawing

AI summary

A method includes defining areas of ownership for users of a computer system; receiving a proposed modification from a first user of the users, the first user being an owner of the proposed modification, wherein a set of the users are stakeholders in the proposed modification; and receiving decisions from a selected set of the stakeholders on approval of the proposed modification. Upon receiving the approvals from all of the selected stakeholders, the owner is granted permission to implement the proposed modification.