User Permission Authorization via Segmented Approval Nodes
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing role-based access control methods in large-scale application systems are cumbersome and prone to errors due to complex permission management, especially when user permissions change or when authorizing approval processes and nodes, leading to increased workload and potential security vulnerabilities.
Innovation Solution
A method that allows for the selection of a user in a system, displaying all approval processes and nodes, and authorizing permissions in a straightforward manner, where roles are treated as independent entities, enabling quick and accurate permission management without the need to consider commonalities among multiple users, facilitating dynamic authorization and reducing errors.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If role-based access control is used to manage permissions in large-scale application systems, then permission management becomes more organized and compliant with business specifications, but the complexity of managing and authorizing permissions increases significantly
Solution Approach 1:
The patent segments permission management into three distinct layers: data scope permissions (which data can be accessed), business permission templates (pre-defined business operation permissions), and button permissions (specific UI action permissions). This segmentation allows each layer to be managed independently, reducing the overall complexity while maintaining comprehensive control and compliance.
2Productivity
If conventional role-based authorization is used where one role corresponds to multiple users, then authorization efficiency is improved, but flexibility to modify individual user permissions without affecting other users is lost
Solution Approach 1:
The patent applies local quality by allowing different permission configurations at different levels: role-level permissions provide general authorization for efficiency, while user-level custom permissions allow individual adjustments without affecting other users. This enables both bulk authorization and granular customization coexist, resolving the contradiction between efficiency and flexibility.
3Measurement precision
If direct authorization of permissions to users is performed, then permission control precision is improved, but the workload and time required for authorization increases significantly
Solution Approach 1:
The patent implements preliminary action by pre-defining business permission templates that contain commonly needed permission combinations. These templates are prepared in advance and can be quickly assigned to users or roles, eliminating the need to manually configure each permission individually. This maintains precise permission control while dramatically reducing authorization time and workload.
4Adaptability or versatility
If multiple roles are created to accommodate changing user permissions, then permission adaptability is improved, but the number of roles and management complexity increases
Solution Approach 1:
The patent applies dynamics by making permission assignments flexible and adjustable at any time without requiring role restructuring. Users can be dynamically added or removed from roles, and permissions can be modified through the layered permission system without creating new roles. This maintains high adaptability while avoiding the complexity accumulation that occurs with static role-based approaches.
Data Source
AI summary
A method for authorizing an approval process and approval node thereof for a user is provided. The method for authorizing an approval process a user comprises: selecting a user in a system; displaying all approval processes in the system, and displaying current usage permission states of the selected user with respect to the approval processes; and authorizing usage permissions of the approval processes to the selected user. All of the approval processes or all approval nodes in the system are displayed after the user is selected, without omitting any approval process or any approval node, thereby facilitating quick authorization of related permissions to the user.


