Selective Document Authorization Interface for Data Privacy
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current systems grant all document data permissions to third-party applications at once, leading to potential data leaks when servers are attacked, as users cannot selectively authorize access to specific document data.
Innovation Solution
A method and apparatus that display a document source control in a target application, allowing users to selectively authorize specific document data by displaying a to-be-authorized-document list and a first authorized-document list, ensuring that only authorized data is accessible to the target application.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If the document application grants all document data permissions to the target application at once, then the target application can access all document data without restriction, but the user's private document data is exposed and vulnerable to leakage when the server is attacked
Solution Approach 1:
The patent segments the authorization process by dividing document data into individually selectable items in a to-be-authorized-document list, rather than granting all permissions at once. Users can select specific documents to authorize, implementing fine-grained control that prevents exposure of unauthorized private data while maintaining convenience for authorized documents.
Solution Approach 2:
The patent applies local quality by allowing different authorization states for different document data items. Each document in the to-be-authorized-document list can be independently authorized or unauthorized, creating localized permission settings rather than a blanket authorization approach. This enables private documents to remain protected while specific documents are made accessible.
2Productivity
If the document application grants permissions on all document data to the target application at a time, then the target application can access all document data, but not all document data needs to be used and private document data may be leaked
Solution Approach 1:
The patent implements preliminary action by displaying the to-be-authorized-document list before granting actual access permissions. Users pre-select which documents to authorize in advance, allowing the system to prepare the authorization state beforehand. This preliminary selection process ensures that only necessary documents are authorized, maintaining security while enabling efficient access to authorized documents.
Solution Approach 2:
The patent applies dynamics by making the authorization state changeable and adaptable. The system transitions from a static all-or-nothing authorization model to a dynamic model where users can selectively authorize specific documents. The to-be-authorized-document list allows flexible adjustment of permissions based on actual needs, improving both security and authorization efficiency.
3Reliability
If the system displays a to-be-authorized-document list for user selection, then users can selectively authorize specific documents, but the authorization process becomes more complex
Solution Approach 1:
The patent extracts the authorization selection process into a separate to-be-authorized-document list interface, isolating it from the main application flow. This extracted list presents only documents that need authorization, rather than all documents in the system. By taking out the authorization complexity into a dedicated interface, the system maintains simplicity in the main application while providing comprehensive security controls in the authorization layer.
Data Source
AI summary
A data processing method includes: displaying a document source control in a target application; displaying a to-be-authorized-document list in response to a trigger operation on the document source control, the to-be-authorized-document list including one or more document titles, the one or more document titles including a title that is in a document application and that corresponds to document data associated with a first object, and the first object being logged in to the document application through the target application; and displaying a first authorized-document list including a first title in response to a trigger operation on the to-be-authorized-document list (S103), the first title being a triggered document title, and the target application having a permission to perform service processing on document data corresponding to the first title.


