Minerva: Security and Authorization

When working on the internet, ensuring the security of your system and your information is extremely important. Recent developments in internet security show that this issue has reached a highly positive point. Today, many banks all over the world conduct transactions over the internet, and many companies run e-commerce operations over the internet.

Fundamentally, security can be assessed under 3 main categories:

  • Security of the computer system
  • Internet traffic security
  • Functional security of the application

System Security

The security of the computer system and the local network means that external users who wish to access your system can perform only the operations that have been predefined and authorized by you.

Firewalls and similar products are used to provide this security. These products obtain information about the network computers and servers under protection and allow only predetermined functions to be used.

Minerva is compatible with advanced security methods such as fingerprint, biometric signature, access using cryptographic devices, and IP restriction (allowing only predefined IPs or local IPs).

Internet Traffic Security

While the internet offers us unlimited opportunities with its open architecture, it can create potential problems for protecting the confidentiality and integrity of the data packets traveling over the internet. Many products have been developed to solve this problem. One of the most widely used and approved is the SSL (Secure Sockets Layer) protocol developed by Netscape, which solves the problem of internet traffic security. The SSL protocol encrypts the traffic between two parties on the internet and ensures that integrity and confidentiality are preserved. To use this system, the browser you use must support the SSL protocol.

Minerva Functional Security

In the internet environment, it is very important to determine and authorize which information can be viewed and which operations can be performed by users, in addition to ensuring system and traffic security. For this reason, Minerva provides you with many levels of security and authorization for different purposes.

User Code and Password

The user code and password consist of 50 characters each, and a user who wishes to access the system must enter both the user code and the password. The combination of ASCII codes for these two fields: 50 * 50.

In order for each user to log in to the system, they must enter both a user code and a password. Every user must have a user code in the system. Multiple users cannot use the system with a single user code. If different users attempt to log in to the system with the same user code, only the most recent login is accepted by the system.

Session Timeout

If a user does not perform any operation for a certain period (a parametrically definable number of minutes) and this period is exceeded, the system asks the user to log in again. In this way, the system protects itself in case the user forgets to log out.

Functional Authorizations of the Program

For companies with extensive operations, security is of vital importance. Minerva has features for restricting operations and operation methods on a per-user basis. Unless authorized, users cannot perform operations, cannot edit or cancel an operation performed by others, and even their viewing of documents can be restricted.

In Minerva, program authorizations are set according to user authorization groups. Every user must belong to an authorization group. Authorization groups are set up at two levels of authorization.

  • Intra-Module Operation Authorization (Functional Authorizations)
  • Module Report Authorizations

First-level authorization is on a per-module basis, and if a user group is not authorized to work with a module, the users of that user group cannot see that module and its items in the system menu.

Once authorization has been granted for a module, authorization for the module’s functions can also be granted in the same way, following a tree logic. Unauthorized functions likewise cannot be seen in the system menu.

Functions such as entering, viewing, deleting, and editing information depend on authorizations. In this way, a user can perform an operation only if they have been authorized to do so.

Usage Time Restriction

Usage hours on weekdays can be set for each user group. In this way, the days and hours during which users can use the system can be determined.

Audit Trails

In any data operation, Minerva keeps the user code, the transaction date, and the time, and can report them at any time for audit purposes.

  • The ability to lock documents according to user authorizations
  • The ability to determine the number of copies to be printed for all documents
  • Disallowing operations on records whose accounting transactions have been completed
  • The ability to lock all records after the approved journal has been printed
  • Automatic printing definitions after a document is saved
  • User-based audit trail reports
  • Restriction of working on holidays

Minerva Audit Features

Database Archive

Minerva runs on an Oracle database. When Oracle is run in archive mode, the logs of all transactions are kept automatically. In this way, the complete records of changes can be accessed.

Example: When an update is made on a personnel record, Oracle automatically saves this change to the archive system. Even if changes to the same personnel record have been made 100 times by different users, the records of these 100 changes will be kept separately.

In Minerva, when a change is made to a record, since every record carries a user code, the information about the changed fields can be recorded and tracked. This feature is activated at the user’s request, because it reduces system performance by 10-20% and requires more disk space.

Minerva User Logs

In Minerva, when the user-based USER_LOG parameter is set to "yes" for a user, all operations performed by that user can be tracked.

Low IT Cost

  • Minerva can run on the Linux operating system; therefore, since Linux is free, you do not have to pay high license fees.
  • Minerva does not require advanced hardware systems.
  • Programs are not installed on terminals. Therefore, per-user license costs, computer maintenance costs, and hardware upgrade costs are no longer an issue.

In this way, you can have a reliable, low-cost infrastructure with high security.

Contact Us