Information Processing Apparatus Base Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing server access systems allow terminals with valid certificates to use servers from unmanaged locations, preventing secure access restrictions.
Innovation Solution
An information processing apparatus that detects requests from terminals and transmits validation requests to a CRL distribution server to ensure only terminals within a designated base can access external servers by managing certificate validity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If certificate authentication is simply validated, then terminal can use server as long as certificate is valid, but terminal may use server from outside base which is incapable of being managed
Solution Approach 1:
The patent applies preliminary action by pre-invalidating certificates for terminals outside the base before they attempt to access the server. The information processing apparatus detects the terminal's location, and if determined to be outside the base, proactively invalidates the certificate through the CRL distribution server, preventing unauthorized access before it occurs.
Solution Approach 2:
The patent introduces an intermediary mechanism by inserting an additional validation step between the terminal and server communication. The information processing apparatus acts as an intermediary that intercepts requests, validates terminal location, and manages certificate validity status, thereby controlling access without requiring changes to the original server or terminal systems.
2Reliability
If terminal location is monitored to restrict access, then only terminals in base can use server, but system complexity increases
Solution Approach 1:
The patent applies self-service by having the terminal itself provide location information to the information processing apparatus. The terminal includes its own identification data that reveals its location status, eliminating the need for complex external monitoring infrastructure. The system leverages existing terminal capabilities to determine whether it is inside or outside the base.
Solution Approach 2:
The information processing apparatus serves as a simplified intermediary that handles the complexity of access control logic centrally. Rather than distributing complex monitoring functions across multiple systems, a single apparatus manages certificate validation and location verification, reducing overall system complexity while maintaining security.
Data Source
AI summary
An information processing apparatus includes a processor programmed to: detect a request submitted from a terminal to an external server providing a service; and upon a determination that the detected request is submitted from the terminal located in a base, transmit a validation request for validating a certificate of the terminal to a CRL distribution server in which the certificate of the terminal is invalid.


