Time-Aware Access Control for Transactional Data Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional approaches to securing information in organizational structures lack flexibility to adapt to changes in corporate processes or personnel, leading to issues with access permissions and accurate compensation recognition during employee transfers.

Innovation Solution

A method and system that utilize a hierarchical data structure to identify entities associated with transactional information, determine subsets of data based on relationships, and authorize access at specific points in time, allowing for flexible security management and retention of permissions across organizational changes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional security mechanisms are used to secure information based on current position, then confidentiality is maintained during organizational changes, but employees lose access to historical transactional information needed for accurate compensation verification

Engineering Contradiction:
Improvecompensation verification accuracyVSAvoidflexibility to adapt to organizational changes
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent adds a temporal dimension to security permissions by implementing time-based access control. Instead of only position-based permissions, the system now considers when access is requested versus when the data was generated. This allows Cynthia to access her historical span of access 102 even after moving to position B, because the access request is for a past time period when she held supervisory role over E and F.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Solution Approach 2:

The security system transitions from static position-based permissions to dynamic time-aware permissions. The system dynamically evaluates both the user's current position and the time period of the data being accessed. This enables flexible adaptation to organizational changes while preserving historical access rights for compensation verification purposes.

Inventive Principle:
Principle #15Dynamics

2Reliability

If access permissions are strictly tied to current organizational position, then security and confidentiality are maintained, but employees cannot verify compensation for work performed in previous roles

Engineering Contradiction:
Improvecompensation accuracyVSAvoidaccess to historical data
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system performs preliminary evaluation of the access request by checking both the user's historical positions and the time period of the requested data. Before granting or denying access, the system proactively verifies whether the user held the appropriate position during the time the data was generated, allowing Cynthia to verify her compensation for previous roles.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces a time-based intermediary layer between the user and the data. Instead of direct position-based access, the system mediates access by evaluating the temporal relationship between when the user held a position and when the data was generated. This intermediary mechanism enables Cynthia to access historical data for compensation verification while maintaining security controls.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If the system allows flexible access to historical transactional information, then employees can verify compensation accurately, but security and confidentiality may be compromised

Engineering Contradiction:
Improveflexibility for compensation verificationVSAvoidsecurity risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies different security rules to different time periods and data types. Instead of a uniform security policy, the system grants flexible access for historical compensation verification while maintaining strict security for current operational data. This localized quality approach allows Cynthia to access her historical span of access 102 for verification purposes while preventing unauthorized access to current sensitive information.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system segments access permissions by time period and data context. Historical transactional data is separated from current operational data, with different access rules applying to each segment. This segmentation allows Cynthia to access historical data for compensation verification without compromising security of current organizational information.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS7890394B2Secure access to transaction based information
Publication Date: 2011.02.15 ORACLE INT CORP
  • US7890394B2 patent drawing
  • US7890394B2 patent drawing
  • US7890394B2 patent drawing

AI summary

The present invention includes a system and method for securing information and accessing secured information. In accordance with an embodiment of the present invention, information is secured by associating a context in which the information was generated, for example. To access the secured information, a user provides a point in time and a user identifier, which are used to determine whether that user is authorized to access the information.