Data Management Server Whitelist Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In manufacturing data management systems, there is a risk of unauthorized applications accessing sensitive processing data from edge devices, which can compromise security and data privacy by allowing unintended applications to utilize the data stored in development environments.

Innovation Solution

A data management system that includes a control unit and database, with a data use condition information management unit to record and manage which applications are permitted to access specific data files, ensuring only designated applications can access the data, and a data transmission unit that registers and transmits data use conditions when providing data from outside the server.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If processing data is stored in a database in a decrypted state for application access, then application functionality is improved, but data security deteriorates

Engineering Contradiction:
Improveapplication data accessVSAvoiddata security risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary action by embedding availability application information (whitelist) into the data file before transmission. This pre-configured security mechanism ensures that only designated applications can access the data upon receipt, preventing unauthorized access before it can occur. The whitelist is created in advance by the data provider, specifying which applications are permitted to use the data.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary mechanism through the availability application information that acts as a mediator between the data file and applications. This intermediary layer verifies application permissions before allowing data access, controlling which applications can utilize the data without requiring the data to remain encrypted. The whitelist serves as this intermediary security check.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If data is provided to multiple applications without restriction, then data utility is improved, but data privacy control deteriorates

Engineering Contradiction:
Improvedata reusabilityVSAvoiddata privacy control
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent applies local quality by providing different access permissions to different applications through the availability application information. Instead of uniform access control, the system specifies which particular applications can access the data, creating localized permission settings. This allows selective data sharing where each application receives appropriate access rights based on its designated purpose.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS20240119167A1Data management system, data management server, data management method, data management program, and recording medium
Publication Date: 2024.04.11 FANUC LTD
  • US20240119167A1 patent drawing
  • US20240119167A1 patent drawing
  • US20240119167A1 patent drawing

AI summary

When a data provider provides data to the outside, an application not intended by the data provider to use the data is prevented from doing so. A reception-side server comprises a data usage condition information management unit which: when available application information, in which an application name for allowing access to data provided from outside is set, is added to the data, registers data usage condition information; and when an access request for the data is received from any application, allows access to the data only to applications that are authorized to access the data on the basis of the data usage condition information.