Access Control via Organization Information Matching
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing information processing systems lack effective mechanisms to securely manage access requests from external devices based on organizational IP addresses, leading to potential unauthorized access when global IP addresses are involved.
Innovation Solution
An information processing apparatus with a receiving unit and controller that determines if an external device belongs to the same organization by matching organization information obtained via DNS and WHOIS protocols, and only responds or grants access if the condition is met, using a global IP address determination unit, organization information acquiring unit, organization information matching determination unit, and response controller.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If the system responds to all access requests when having a global IP address, then accessibility and ease of operation are improved, but security and reliability deteriorate due to potential unauthorized access from external organizations
Solution Approach 1:
The patent introduces an organization information matching determination unit as an intermediary between the access request receiver and the response generator. This unit acts as a mediator that verifies whether the accessing apparatus belongs to the same organization as the own apparatus by comparing organization information, thereby enabling secure access control without compromising accessibility for legitimate users
Solution Approach 2:
The patent performs organization information matching determination before granting access to the own apparatus. By preliminarily verifying the organizational affiliation of the accessing apparatus through DNS and WHOIS queries, the system prevents unauthorized access in advance while maintaining open access for legitimate organizational members
2Reliability
If the system verifies organization information for all access requests, then security and reliability are improved, but device complexity and processing time increase
Solution Approach 1:
The patent applies organization information verification selectively rather than universally. The verification process is activated only when specific conditions are met, such as when the own apparatus has a global IP address or when the accessing apparatus appears to be from a different network. This localized application of verification reduces overall system complexity while maintaining security
Solution Approach 2:
The patent divides the access control system into distinct functional modules: a receiving unit for access requests, a global IP address determination unit, an organization information acquiring unit, an organization information matching determination unit, and a response controller. This segmentation allows each module to perform its specific function independently, simplifying the overall system architecture and making the complexity manageable through modular design
3Measurement precision
If the system uses DNS and WHOIS protocols to verify organization information, then accuracy of organization identification is improved, but loss of time and processing duration increase
Solution Approach 1:
The patent implements a tiered verification approach where not all access requests undergo the complete DNS and WHOIS verification process. For requests that appear to be from the same organization based on initial network information, the system may grant access with simplified verification. The full DNS and WHOIS protocol verification is applied selectively to suspicious or external requests, reducing average verification time while maintaining high accuracy for critical decisions
Solution Approach 2:
The patent performs preliminary checks using readily available network information before initiating time-consuming DNS and WHOIS queries. By first examining basic network headers and IP information, the system can quickly identify obviously legitimate or obviously malicious requests, reserving the more time-intensive verification methods for cases where the preliminary check is inconclusive
Data Source
AI summary
An information processing apparatus includes a processor that is programmed to acquire an organization information from another apparatus. In response to determining that: i) an organization information of the information processing apparatus and an organization information of the another apparatus do not match; and (ii) an authentication information set in the information processing apparatus remains to be a default setting, the processor is programmed to make no response to, or reject, an access request from the another apparatus.


