Time-Range Permission Segmentation for Operation Record Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional role-based access control methods in management software systems face challenges in efficiently managing user permissions, particularly in setting dynamic viewing permissions for operation records based on time ranges, leading to information leakage and security vulnerabilities.

Innovation Solution

A method that allows for setting permissions to view operation records within specific time ranges by selecting grantees and viewed objects, with viewing-permission time ranges defined as options such as backwards from a current time, from a start time to a current time, from a deadline to a system initial time, and from a system initial time to a current time, enabling precise control over access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If conventional role-based access control is used to manage user permissions, then permission management can be simplified through role grouping, but users cannot view operation records within specific time ranges leading to information leakage

Engineering Contradiction:
Improvepermission managementVSAvoidinformation security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the viewing permission by dividing it into time-based segments. Instead of granting universal viewing rights to users through roles, the system divides access to operation records into specific time ranges (e.g., current month, current quarter, custom date ranges). This segmentation allows users to view only the operation records within their authorized time segments, preventing information leakage while maintaining ease of role-based management.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If universal viewing permission is granted to users through roles, then users can access all operation records, but information security is compromised and unauthorized access occurs

Engineering Contradiction:
Improveaccess flexibilityVSAvoidinformation leakage
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces dynamic time range parameters into the permission system. The viewing permission is no longer static but dynamically constrained by time ranges that can be configured for each user or role. This allows the system to adapt access flexibility to security requirements by adjusting time ranges (e.g., allowing users to view only current month records or custom date ranges), thereby maintaining versatility while preventing unauthorized access to historical records.

Inventive Principle:
Principle #15Dynamics

3Reliability

If detailed time range control is implemented for viewing permissions, then information security is improved, but permission management complexity increases

Engineering Contradiction:
Improveinformation securityVSAvoidpermission management system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent adds a time dimension to the traditional role-based permission model. Instead of managing permissions solely through user-role-resource relationships, the system introduces time range as an additional dimension. This allows security control through time-based parameters (start time, end time, current month, current quarter, etc.) without fundamentally changing the role-based structure, thereby improving security while keeping the management system relatively simple.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS11586747B2Method for setting operating record viewing right based on time period
Publication Date: 2023.02.21 CHENGDU QIANNIUCAO INFORMATION TECH CO LTD
  • US11586747B2 patent drawing
  • US11586747B2 patent drawing
  • US11586747B2 patent drawing

AI summary

A method for setting a permission to view an operation record based on a time range is disclosed in the present invention, including: selecting a grantee; setting one or more viewed objects for each grantee, wherein said grantee and said viewed object are the same type as a role, a user, and an employee; and setting a viewing-permission time range for each grantee, wherein said grantee obtains the permission to view the operation records of its corresponding viewed object within the viewing-permission time range of the grantee. In the present invention, the grantee can be authorized to view operation records of the viewed object within a certain time range according to actual requirements, and cannot view the operation records of the viewed object out of the time range, thus satisfying the requirement for viewing operation records of the viewed object in various time-limited cases, reducing the possibility that the operation records are known by irrelevant personnel, and improving information security of the company.