Dual-Layer Document Access Control via User-Terminal Binding

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing document management systems lack sufficient leakage countermeasures, particularly when documents are accessed using unsecured terminal devices, increasing the risk of information leakage.

Innovation Solution

An information processing apparatus that designates both the user and terminal device as transmission destinations for documents, encrypting and formatting them securely, and managing metadata to ensure only authorized users can access and decrypt the documents.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a system allows any designated user to access documents with any terminal device, then document accessibility and ease of operation are improved, but document security and leakage prevention deteriorate

Engineering Contradiction:
Improvedocument accessibilityVSAvoiddocument security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the access authorization into two independent dimensions: user identity and terminal device. Instead of granting access based solely on user designation, the system requires both the designated user and the specific terminal device to be authorized. This segmentation creates a dual-layer security mechanism where document access rights are divided between user-level permissions and device-level bindings, preventing unauthorized access even if one layer is compromised.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a metadata structure as an intermediary that mediates between the document and the access request. This metadata contains both user identification information and terminal device binding information, acting as a gatekeeper that verifies both dimensions of authorization before permitting document access. The metadata serves as the intermediary validation layer that enforces the dual-authorization requirement.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If a system binds documents to specific terminal devices, then document security is improved, but device compatibility and versatility deteriorate

Engineering Contradiction:
Improveleakage preventionVSAvoidterminal compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic terminal binding where the association between documents and terminal devices is not fixed but can be flexibly managed. The system allows the designated user to specify which terminal devices are authorized for document access, and these bindings can be updated, added, or removed as needed. This dynamic approach enables the system to adapt to changing device environments while maintaining security through controlled authorization rather than rigid restrictions.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent creates a universal access control framework that works across different terminal device types. The metadata structure and authorization mechanism are designed to be device-agnostic, supporting various terminal types (computers, mobile devices, tablets, etc.) as long as they meet the authorization criteria. The system's multi-functionality allows it to handle both strict single-device binding and flexible multi-device authorization scenarios within the same framework.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11178292B2Information processing apparatus, protection processing apparatus and terminal device for limiting access to a document
Publication Date: 2021.11.16 FUJIFILM BUSINESS INNOVATION CORP
  • US11178292B2 patent drawing
  • US11178292B2 patent drawing
  • US11178292B2 patent drawing

AI summary

An information processing apparatus includes: a designation unit that allows a user of a transmission source of a document to designate a transmission destination user and a transmission destination terminal; and a transmission unit that transmits the document and transmission destination information indicative of the transmission destination user and the transmission destination terminal designated with the designation unit to an apparatus that transmits the document to the transmission destination terminal.