Access Control Apparatus for Electronic File Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing access control systems fail to effectively restrict access to electronic files based on predetermined access control information, allowing unauthorized software to access or manipulate sensitive data.

Innovation Solution

An access control apparatus and system that utilize a control unit to enforce access restrictions by determining whether software meets predetermined permission or denial conditions, using a management server to provide access control information and manage encryption/decryption of electronic files, ensuring only authorized software can access and manipulate the files.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If access control information is not enforced, then software can freely access electronic files, but data security is compromised and unauthorized access occurs

Engineering Contradiction:
Improvedata securityVSAvoidsoftware accessibility
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces an access control apparatus as an intermediary component between software and electronic files. This apparatus evaluates access control information (such as digital rights management data, file metadata, or authentication credentials) to determine whether software is authorized to access specific files, thereby enabling security enforcement without directly blocking legitimate software operations

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The access control apparatus performs preliminary evaluation of access control information before software can access electronic files. By checking authorization status in advance and only permitting access when conditions are satisfied, the system prevents unauthorized access before it can occur, rather than reacting after security breaches

Inventive Principle:
Principle #10Preliminary action

2Reliability

If access control evaluation is performed for every file access, then data security is enhanced, but processing time increases

Engineering Contradiction:
Improveaccess control enforcementVSAvoidaccess evaluation time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The access control apparatus applies partial evaluation by focusing only on critical access control criteria rather than performing exhaustive checks on all possible file attributes. This selective evaluation approach maintains security enforcement while reducing the time overhead associated with comprehensive access control verification

Inventive Principle:
Principle #16Partial or excessive action

3Measurement precision

If comprehensive access control information is stored, then access control precision is improved, but device complexity increases

Engineering Contradiction:
Improveaccess control precisionVSAvoidinformation storage structure
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The access control information is segmented into distinct, manageable components such as authorization credentials, file metadata, and evaluation criteria. This segmentation allows the access control apparatus to process and evaluate specific portions of information independently, maintaining high access control precision while avoiding the complexity of managing monolithic access control data structures

Inventive Principle:
Principle #1Segmentation

Data Source

PatentEP2933751B1Access control device, program and access control system
Publication Date: 2019.08.14 DIGITAL ARTS
  • EP2933751B1 patent drawingFigure 1
  • EP2933751B1 patent drawingFigure 2
  • EP2933751B1 patent drawingFigure 3~4

AI summary

An access control apparatus comprises a control unit that, based on predetermined access control information, restricts access to an electronic file by software that is permitted to access or prohibited from accessing the electronic file. An access control system comprises: an access control apparatus that has a control unit that, based on predetermined access control information, restricts access to an electronic file by software that is permitted to access or prohibited from accessing the electronic file; and a management apparatus that is provided outside the access control apparatus, and provides, to the access control apparatus, at least one of the predetermined access control information and a judgment result based on the predetermined access control information.