Time-Range Permission Segmentation for Operation Record Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional role-based access control methods in management software systems face challenges in efficiently managing user permissions, particularly in setting dynamic viewing permissions for operation records based on time ranges, leading to information leakage and security vulnerabilities.
Innovation Solution
A method that allows for setting permissions to view operation records within specific time ranges by selecting grantees and viewed objects, with viewing-permission time ranges defined as options such as backwards from a current time, from a start time to a current time, from a deadline to a system initial time, and from a system initial time to a current time, enabling precise control over access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If conventional role-based access control is used to manage user permissions, then permission management can be simplified through role grouping, but users cannot view operation records within specific time ranges leading to information leakage
Solution Approach 1:
The patent segments the viewing permission by dividing it into time-based segments. Instead of granting universal viewing rights to users through roles, the system divides access to operation records into specific time ranges (e.g., current month, current quarter, custom date ranges). This segmentation allows users to view only the operation records within their authorized time segments, preventing information leakage while maintaining ease of role-based management.
2Adaptability or versatility
If universal viewing permission is granted to users through roles, then users can access all operation records, but information security is compromised and unauthorized access occurs
Solution Approach 1:
The patent introduces dynamic time range parameters into the permission system. The viewing permission is no longer static but dynamically constrained by time ranges that can be configured for each user or role. This allows the system to adapt access flexibility to security requirements by adjusting time ranges (e.g., allowing users to view only current month records or custom date ranges), thereby maintaining versatility while preventing unauthorized access to historical records.
3Reliability
If detailed time range control is implemented for viewing permissions, then information security is improved, but permission management complexity increases
Solution Approach 1:
The patent adds a time dimension to the traditional role-based permission model. Instead of managing permissions solely through user-role-resource relationships, the system introduces time range as an additional dimension. This allows security control through time-based parameters (start time, end time, current month, current quarter, etc.) without fundamentally changing the role-based structure, thereby improving security while keeping the management system relatively simple.
Data Source
AI summary
A method for setting a permission to view an operation record based on a time range is disclosed in the present invention, including: selecting a grantee; setting one or more viewed objects for each grantee, wherein said grantee and said viewed object are the same type as a role, a user, and an employee; and setting a viewing-permission time range for each grantee, wherein said grantee obtains the permission to view the operation records of its corresponding viewed object within the viewing-permission time range of the grantee. In the present invention, the grantee can be authorized to view operation records of the viewed object within a certain time range according to actual requirements, and cannot view the operation records of the viewed object out of the time range, thus satisfying the requirement for viewing operation records of the viewed object in various time-limited cases, reducing the possibility that the operation records are known by irrelevant personnel, and improving information security of the company.


