User Permission Authorization via Segmented Approval Nodes

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing role-based access control methods in large-scale application systems are cumbersome and prone to errors due to complex permission management, especially when user permissions change or when authorizing approval processes and nodes, leading to increased workload and potential security vulnerabilities.

Innovation Solution

A method that allows for the selection of a user in a system, displaying all approval processes and nodes, and authorizing permissions in a straightforward manner, where roles are treated as independent entities, enabling quick and accurate permission management without the need to consider commonalities among multiple users, facilitating dynamic authorization and reducing errors.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If role-based access control is used to manage permissions in large-scale application systems, then permission management becomes more organized and compliant with business specifications, but the complexity of managing and authorizing permissions increases significantly

Engineering Contradiction:
Improvepermission management complianceVSAvoidpermission management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments permission management into three distinct layers: data scope permissions (which data can be accessed), business permission templates (pre-defined business operation permissions), and button permissions (specific UI action permissions). This segmentation allows each layer to be managed independently, reducing the overall complexity while maintaining comprehensive control and compliance.

Inventive Principle:
Principle #1Segmentation

2Productivity

If conventional role-based authorization is used where one role corresponds to multiple users, then authorization efficiency is improved, but flexibility to modify individual user permissions without affecting other users is lost

Engineering Contradiction:
Improveauthorization efficiencyVSAvoidpermission modification flexibility
Core Design Contradiction:
ProductivityVSAdaptability or versatility

Solution Approach 1:

The patent applies local quality by allowing different permission configurations at different levels: role-level permissions provide general authorization for efficiency, while user-level custom permissions allow individual adjustments without affecting other users. This enables both bulk authorization and granular customization coexist, resolving the contradiction between efficiency and flexibility.

Inventive Principle:
Principle #3Local quality

3Measurement precision

If direct authorization of permissions to users is performed, then permission control precision is improved, but the workload and time required for authorization increases significantly

Engineering Contradiction:
Improvepermission control precisionVSAvoidauthorization time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent implements preliminary action by pre-defining business permission templates that contain commonly needed permission combinations. These templates are prepared in advance and can be quickly assigned to users or roles, eliminating the need to manually configure each permission individually. This maintains precise permission control while dramatically reducing authorization time and workload.

Inventive Principle:
Principle #10Preliminary action

4Adaptability or versatility

If multiple roles are created to accommodate changing user permissions, then permission adaptability is improved, but the number of roles and management complexity increases

Engineering Contradiction:
Improvepermission adaptabilityVSAvoidrole management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent applies dynamics by making permission assignments flexible and adjustable at any time without requiring role restructuring. Users can be dynamically added or removed from roles, and permissions can be modified through the layered permission system without creating new roles. This maintains high adaptability while avoiding the complexity accumulation that occurs with static role-based approaches.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS11750616B2Method for authorizing approval processes and approval nodes thereof for user
Publication Date: 2023.09.05 CHENGDU QIANNIUCAO INFORMATION TECH CO LTD
  • US11750616B2 patent drawing
  • US11750616B2 patent drawing
  • US11750616B2 patent drawing

AI summary

A method for authorizing an approval process and approval node thereof for a user is provided. The method for authorizing an approval process a user comprises: selecting a user in a system; displaying all approval processes in the system, and displaying current usage permission states of the selected user with respect to the approval processes; and authorizing usage permissions of the approval processes to the selected user. All of the approval processes or all approval nodes in the system are displayed after the user is selected, without omitting any approval process or any approval node, thereby facilitating quick authorization of related permissions to the user.