Content Management Apparatus Cross-Service Group Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cloud services face challenges in configuring document management systems to allow only specific group participants to access documents shared via microblog services, due to separate security domains and user management systems.

Innovation Solution

A content management apparatus that associates content information with group information from a posting management service, acquiring and determining access control based on user participation groups, ensuring only authorized users can view or access shared documents.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If document management service and microblog service are provided as separate services with different security domains, then each service can maintain its own user management independently, but the document management service cannot control access based on microblog service group participation

Engineering Contradiction:
Improveaccess control capabilityVSAvoidsystem integration complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary mechanism that bridges the document management service and microblog service through standardized APIs. The document management service acts as an intermediary that can query group information from the microblog service and use it for access control decisions, enabling cross-service coordination without direct coupling. This resolves the contradiction by allowing access control based on group participation while maintaining separate service architectures.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements a universal access control framework that can work with multiple service types (document management, microblogging) through a common interface. The system uses standardized authentication tokens and group information structures that can be applied across different services, enabling the document management service to leverage microblog service group data without requiring service-specific customizations. This multi-functional approach resolves the contradiction between service independence and integrated access control.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Ease of operation

If URL for document is shared via microblog service, then document can be accessed by users who see the shared link, but users outside the specific group can also access the document

Engineering Contradiction:
Improvedocument sharing easeVSAvoidaccess security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements a feedback mechanism where the document management service continuously verifies the requester's group membership status against the microblog service before granting document access. When a user attempts to access a shared document, the system queries the microblog service to confirm active group participation, and only grants access if the user is currently a member of the designated group. This feedback loop resolves the contradiction by maintaining easy sharing through URL distribution while ensuring security through real-time verification.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent performs preliminary authentication and group membership verification before allowing document access. Instead of relying solely on URL-based access control, the system pre-validates the user's credentials and group affiliation through the microblog service's authentication mechanism. This preliminary action ensures that only authorized group members can access documents, even if they obtain the sharing URL, thus resolving the security concern while preserving ease of sharing.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9971901B2Content management apparatus and content management method
Publication Date: 2018.05.15 CANON KK
  • US9971901B2 patent drawing
  • US9971901B2 patent drawing
  • US9971901B2 patent drawing

AI summary

A content management apparatus as an embodiment of the present invention associates content information on content with group information on a user participation group in a posting management service that approves control for the content, and stores the associated information. The apparatus then acquires group information on the user participation group from the posting management service, upon receipt of a content control request. The apparatus determines whether or not the requested control is to be approved, based on the acquired group information and the group information stored in association with the content information on the content. This configuration allows the content management apparatus for managing the content to control access authorization according to setting of the group in the posting management service.