Time-Window Authorization for Mailbox and Instant Messaging Accounts

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional role-based access control methods in management software systems, such as ERP, face challenges in efficiently managing permissions for mailbox and instant messaging accounts, leading to data leakage and increased workload due to complex authorization processes and difficulties in setting time-limited permissions.

Innovation Solution

A method that allows for the selection of grantees and operated accounts, with permission time ranges set to specific periods, including options based on relation times, enabling granular control over access to content within defined time frames, reducing data leakage and improving security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional role-based access control is used to authorize mailbox and instant messaging accounts, then permission management can be implemented, but data leakage occurs and security is compromised

Engineering Contradiction:
Improvedata securityVSAvoiddata leakage
Core Design Contradiction:
ReliabilityVSObject-generated harmful factors

Solution Approach 1:

The patent segments permission authorization into two independent dimensions: functional permissions (what operations can be performed) and temporal permissions (when operations can be performed). This is achieved by separating the authorization process into functional permission settings and time range settings, allowing independent control over each aspect. The temporal dimension is further segmented into start time and end time parameters, enabling precise time-window based access control.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces dynamic time range authorization that allows permissions to automatically become valid or invalid based on time conditions. The authorization system dynamically adjusts access rights by evaluating whether the current time falls within the authorized time range, enabling automatic activation and deactivation of permissions without manual intervention. This dynamic approach replaces static role-based permissions with time-aware adaptive authorization.

Inventive Principle:
Principle #15Dynamics

2Ease of operation

If conventional role-based access control is used, then permission management is possible, but the authorization process becomes complex and workload increases

Engineering Contradiction:
Improveauthorization process simplicityVSAvoidauthorization process complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent segments the authorization interface into distinct functional modules: grantee selection, functional permission selection, and time range setting. Each module handles a specific aspect of authorization independently, making the overall process more manageable and less overwhelming for users. The segmentation allows users to focus on one aspect at a time rather than configuring all permissions simultaneously.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements preliminary action by providing predefined time range templates and common permission sets that can be selected without detailed configuration. The system pre-configures standard authorization scenarios, allowing users to quickly apply common permission patterns. This reduces the effort required for routine authorization tasks while maintaining the ability to customize when needed.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11303650B2Method for authorizing permission to operate content of mailbox account and instant messaging account in system
Publication Date: 2022.04.12 CHENGDU QIANNIUCAO INFORMATION TECH CO LTD
  • US11303650B2 patent drawing
  • US11303650B2 patent drawing
  • US11303650B2 patent drawing

AI summary

A method for authorizing a permission to operate content in a mailbox account or an instant messaging account in a system is disclosed in the present invention. The method for authorizing a permission to operate content in a mailbox account in a system includes: selecting one or more grantees; selecting one or more operated mailbox accounts; setting a permission time range, wherein said permission time range includes one or more of the following four types: a time range from a time point, which is determined by going backwards from a current time for a fixed time length, to the current time, a time range from a start time to a current time, a time range from a deadline to a system initial time, and a time range from a start time to a deadline; and setting a permission for said grantee to operate content within the permission time range in the operated mailbox account. According to the present invention, the permission can be authorized for the grantee to view data information within a certain time range in the operated mailbox account or the operated instant messaging account according to actual requirements.