Time-Window Authorization for Mailbox and Instant Messaging Accounts
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional role-based access control methods in management software systems, such as ERP, face challenges in efficiently managing permissions for mailbox and instant messaging accounts, leading to data leakage and increased workload due to complex authorization processes and difficulties in setting time-limited permissions.
Innovation Solution
A method that allows for the selection of grantees and operated accounts, with permission time ranges set to specific periods, including options based on relation times, enabling granular control over access to content within defined time frames, reducing data leakage and improving security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional role-based access control is used to authorize mailbox and instant messaging accounts, then permission management can be implemented, but data leakage occurs and security is compromised
Solution Approach 1:
The patent segments permission authorization into two independent dimensions: functional permissions (what operations can be performed) and temporal permissions (when operations can be performed). This is achieved by separating the authorization process into functional permission settings and time range settings, allowing independent control over each aspect. The temporal dimension is further segmented into start time and end time parameters, enabling precise time-window based access control.
Solution Approach 2:
The patent introduces dynamic time range authorization that allows permissions to automatically become valid or invalid based on time conditions. The authorization system dynamically adjusts access rights by evaluating whether the current time falls within the authorized time range, enabling automatic activation and deactivation of permissions without manual intervention. This dynamic approach replaces static role-based permissions with time-aware adaptive authorization.
2Ease of operation
If conventional role-based access control is used, then permission management is possible, but the authorization process becomes complex and workload increases
Solution Approach 1:
The patent segments the authorization interface into distinct functional modules: grantee selection, functional permission selection, and time range setting. Each module handles a specific aspect of authorization independently, making the overall process more manageable and less overwhelming for users. The segmentation allows users to focus on one aspect at a time rather than configuring all permissions simultaneously.
Solution Approach 2:
The patent implements preliminary action by providing predefined time range templates and common permission sets that can be selected without detailed configuration. The system pre-configures standard authorization scenarios, allowing users to quickly apply common permission patterns. This reduces the effort required for routine authorization tasks while maintaining the ability to customize when needed.
Data Source
AI summary
A method for authorizing a permission to operate content in a mailbox account or an instant messaging account in a system is disclosed in the present invention. The method for authorizing a permission to operate content in a mailbox account in a system includes: selecting one or more grantees; selecting one or more operated mailbox accounts; setting a permission time range, wherein said permission time range includes one or more of the following four types: a time range from a time point, which is determined by going backwards from a current time for a fixed time length, to the current time, a time range from a start time to a current time, a time range from a deadline to a system initial time, and a time range from a start time to a deadline; and setting a permission for said grantee to operate content within the permission time range in the operated mailbox account. According to the present invention, the permission can be authorized for the grantee to view data information within a certain time range in the operated mailbox account or the operated instant messaging account according to actual requirements.


