Access Control via Organization Information Matching

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing information processing systems lack effective mechanisms to securely manage access requests from external devices based on organizational IP addresses, leading to potential unauthorized access when global IP addresses are involved.

Innovation Solution

An information processing apparatus with a receiving unit and controller that determines if an external device belongs to the same organization by matching organization information obtained via DNS and WHOIS protocols, and only responds or grants access if the condition is met, using a global IP address determination unit, organization information acquiring unit, organization information matching determination unit, and response controller.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If the system responds to all access requests when having a global IP address, then accessibility and ease of operation are improved, but security and reliability deteriorate due to potential unauthorized access from external organizations

Engineering Contradiction:
ImproveaccessibilityVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces an organization information matching determination unit as an intermediary between the access request receiver and the response generator. This unit acts as a mediator that verifies whether the accessing apparatus belongs to the same organization as the own apparatus by comparing organization information, thereby enabling secure access control without compromising accessibility for legitimate users

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent performs organization information matching determination before granting access to the own apparatus. By preliminarily verifying the organizational affiliation of the accessing apparatus through DNS and WHOIS queries, the system prevents unauthorized access in advance while maintaining open access for legitimate organizational members

Inventive Principle:
Principle #10Preliminary action

2Reliability

If the system verifies organization information for all access requests, then security and reliability are improved, but device complexity and processing time increase

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies organization information verification selectively rather than universally. The verification process is activated only when specific conditions are met, such as when the own apparatus has a global IP address or when the accessing apparatus appears to be from a different network. This localized application of verification reduces overall system complexity while maintaining security

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent divides the access control system into distinct functional modules: a receiving unit for access requests, a global IP address determination unit, an organization information acquiring unit, an organization information matching determination unit, and a response controller. This segmentation allows each module to perform its specific function independently, simplifying the overall system architecture and making the complexity manageable through modular design

Inventive Principle:
Principle #1Segmentation

3Measurement precision

If the system uses DNS and WHOIS protocols to verify organization information, then accuracy of organization identification is improved, but loss of time and processing duration increase

Engineering Contradiction:
Improveorganization identification accuracyVSAvoidverification time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent implements a tiered verification approach where not all access requests undergo the complete DNS and WHOIS verification process. For requests that appear to be from the same organization based on initial network information, the system may grant access with simplified verification. The full DNS and WHOIS protocol verification is applied selectively to suspicious or external requests, reducing average verification time while maintaining high accuracy for critical decisions

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The patent performs preliminary checks using readily available network information before initiating time-consuming DNS and WHOIS queries. By first examining basic network headers and IP information, the system can quickly identify obviously legitimate or obviously malicious requests, reserving the more time-intensive verification methods for cases where the preliminary check is inconclusive

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10423372B2Information processing apparatus, information processing method, and non-transitory computer readable storage medium
Publication Date: 2019.09.24 FUJIFILM BUSINESS INNOVATION CORP
  • US10423372B2 patent drawing
  • US10423372B2 patent drawing
  • US10423372B2 patent drawing

AI summary

An information processing apparatus includes a processor that is programmed to acquire an organization information from another apparatus. In response to determining that: i) an organization information of the information processing apparatus and an organization information of the another apparatus do not match; and (ii) an authentication information set in the information processing apparatus remains to be a default setting, the processor is programmed to make no response to, or reject, an access request from the another apparatus.