Access Control Scenario Filtering for Image Processing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In image processing apparatuses, service personnel face difficulties in executing adjustment operations due to complex access rights management, leading to unnecessary operations and potential errors, as they must repeatedly navigate different menu layers to perform tasks, and access rights are often determined after initiating a workflow, rendering previous actions futile if access is denied at a later stage.
Innovation Solution
A system that includes a management unit for user access rights, a storage unit for scenarios with assigned access levels, and a determination unit to assess executable scenarios before execution, displaying warnings for inaccessible scenarios, thereby preventing unnecessary operations and ensuring secure access management.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If access right determination is performed after workflow execution begins, then access control security is maintained, but previously performed operations become futile and time is wasted
Solution Approach 1:
The system performs preliminary determination of executable scenarios by comparing user access rights with scenario access levels before workflow execution begins. This preliminary action identifies which scenarios the user can execute, allowing the system to prevent selection and execution of inaccessible scenarios in advance, thereby avoiding futile operations while maintaining access control security
2Reliability
If complex access right management is implemented, then security control is improved, but operational complexity and user difficulty increase
Solution Approach 1:
The system automatically performs access right determination by comparing user access rights with scenario access levels without requiring manual intervention or complex user navigation. The determination unit autonomously identifies executable scenarios and the display control unit presents them to users, eliminating the need for users to manually navigate complex access control hierarchies while maintaining secure access management
Solution Approach 2:
The display control unit visually distinguishes executable scenarios from non-executable scenarios through identifiable display characteristics (such as color coding or visual indicators). This visual differentiation allows users to immediately recognize which scenarios they can execute without needing to understand complex access control rules, thereby simplifying operation while maintaining security
3Reliability
If multiple menu layers are required for adjustment operations, then access control granularity is improved, but navigation complexity and operation time increase
Solution Approach 1:
The system extracts the access control determination function from the traditional multi-layer menu navigation structure. Instead of requiring users to navigate through multiple menu layers to access appropriate adjustment functions, the determination unit independently evaluates user access rights against scenario access levels and presents only executable scenarios to the user, eliminating unnecessary navigation steps while preserving access control granularity
Solution Approach 2:
The system performs preliminary filtering of scenarios based on user access rights before presenting them to the user. By determining executable scenarios in advance and displaying only those scenarios, the system eliminates the need for users to navigate through multiple menu layers to find accessible functions, thereby improving operation efficiency while maintaining secure access control
Data Source
AI summary
The apparatus includes a management unit configured to manage an access right that is assigned to each of a plurality of users, and a storage unit configured to store a plurality of scenarios including the adjusting operation of the apparatus and a first access level that is assigned to each of the scenarios. Furthermore, the apparatus determines whether or not a scenario can be executed with the access right given to a user, by comparing the access right of the user with the first access level stored in the storage unit, and displays, before the scenario is executed, at least one of the plurality of scenarios on a display unit such that the determination result can be displayed identifiably.


