Collaboration Service Log Access Control via User Attribute Conditions
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In collaboration services, it is challenging to determine whether information leaks or compliance violations have occurred due to the difficulty in separately referencing operation log records for multiple users involved in group activities, as existing techniques restrict access to operation logs, making it hard to assess issues across users.
Innovation Solution
An information processing system that obtains operation log records and user attributes, sets attribute conditions based on user involvement, and controls access to ensure only authorized users can reference operation logs, using encryption and decryption keys to manage access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If operation log records are restricted to be accessible only by the user who performed the operation, then confidentiality of operation logs is ensured, but the ability to determine whether problems such as information leaks or compliance violations have occurred in collaboration services is deteriorated
Solution Approach 1:
The patent applies local quality by differentiating access permissions for different users based on their involvement in specific collaboration services. Instead of a uniform access restriction, the system grants view permissions to users who are involved in the same collaboration service as the operation log creator, while maintaining restrictions for others. This localized permission approach resolves the contradiction by allowing problem determination within collaboration contexts while preserving confidentiality outside those contexts.
Solution Approach 2:
The patent implements dynamic access control where permission to view operation logs is not static but changes based on the user's involvement in collaboration services. The system dynamically determines which users should have access by checking their participation in the same collaboration service as the log creator. This dynamic permission structure enables both confidentiality protection and problem determination capability depending on the user's role and involvement.
2Ease of operation
If operation log records are made accessible to multiple users in collaboration services, then the ability to monitor compliance and detect information leaks is improved, but the confidentiality and security of operation log records is deteriorated
Solution Approach 1:
The patent applies local quality by granting operation log view permissions selectively to specific users based on their involvement in the same collaboration service as the log creator. This targeted approach allows compliance monitoring and leak detection within the collaboration context while maintaining confidentiality by restricting access to only those users with a legitimate business need. The permission is localized to the collaboration service boundary rather than being universally granted.
Solution Approach 2:
The patent introduces an intermediary mechanism (the collaboration service involvement check) that mediates between the need for log accessibility and the need for confidentiality. The system acts as an intermediary by automatically determining which users should have access based on their participation in the collaboration service, rather than requiring direct user-to-user permission sharing. This intermediary control mechanism enables secure multi-user access without compromising overall log security.
3Reliability
If operation log records are separately referenced for each user, then confidentiality of individual user logs is maintained, but the difficulty in determining whether problems have occurred across multiple users increases
Solution Approach 1:
The patent merges the separate operation log records of multiple users within the same collaboration service into a collectively accessible view. While individual user logs remain confidential to their creators, the system combines access permissions for users involved in the same collaboration service, allowing them to collectively view relevant logs. This merging approach reduces the complexity of cross-user problem determination while preserving individual confidentiality through the collaboration service boundary.
Solution Approach 2:
The patent implements universality by creating a multi-functional access control system that serves both confidentiality protection and cross-user problem determination. The same collaboration service involvement check that protects individual user confidentiality also enables unified access to logs across multiple users within that service. This universal permission mechanism eliminates the need for separate complex permission configurations while maintaining both confidentiality and accessibility goals.
Data Source
AI summary
An information processing system includes one or more processors configured to: obtain one or more operation log records recorded in a collaboration service and information about one or more user attributes of corresponding users who use the collaboration service, the collaboration service supporting information sharing among multiple users; when the collaboration service identified from the content of one operation log record of the one or more operation log records involves multiple users, set an attribute condition on the basis of the information about one or more user attributes, the attribute condition indicating the scope of attributes of users who are allowed to refer to the one operation log record; and exert such control that, in response to an inquiry about reference to the one operation log record from an inquiry user who satisfies the attribute condition, the inquiry user is allowed to refer to the one operation log record.


