Dual-Layer Document Access Control via User-Terminal Binding
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing document management systems lack sufficient leakage countermeasures, particularly when documents are accessed using unsecured terminal devices, increasing the risk of information leakage.
Innovation Solution
An information processing apparatus that designates both the user and terminal device as transmission destinations for documents, encrypting and formatting them securely, and managing metadata to ensure only authorized users can access and decrypt the documents.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a system allows any designated user to access documents with any terminal device, then document accessibility and ease of operation are improved, but document security and leakage prevention deteriorate
Solution Approach 1:
The patent segments the access authorization into two independent dimensions: user identity and terminal device. Instead of granting access based solely on user designation, the system requires both the designated user and the specific terminal device to be authorized. This segmentation creates a dual-layer security mechanism where document access rights are divided between user-level permissions and device-level bindings, preventing unauthorized access even if one layer is compromised.
Solution Approach 2:
The patent introduces a metadata structure as an intermediary that mediates between the document and the access request. This metadata contains both user identification information and terminal device binding information, acting as a gatekeeper that verifies both dimensions of authorization before permitting document access. The metadata serves as the intermediary validation layer that enforces the dual-authorization requirement.
2Reliability
If a system binds documents to specific terminal devices, then document security is improved, but device compatibility and versatility deteriorate
Solution Approach 1:
The patent implements dynamic terminal binding where the association between documents and terminal devices is not fixed but can be flexibly managed. The system allows the designated user to specify which terminal devices are authorized for document access, and these bindings can be updated, added, or removed as needed. This dynamic approach enables the system to adapt to changing device environments while maintaining security through controlled authorization rather than rigid restrictions.
Solution Approach 2:
The patent creates a universal access control framework that works across different terminal device types. The metadata structure and authorization mechanism are designed to be device-agnostic, supporting various terminal types (computers, mobile devices, tablets, etc.) as long as they meet the authorization criteria. The system's multi-functionality allows it to handle both strict single-device binding and flexible multi-device authorization scenarios within the same framework.
Data Source
AI summary
An information processing apparatus includes: a designation unit that allows a user of a transmission source of a document to designate a transmission destination user and a transmission destination terminal; and a transmission unit that transmits the document and transmission destination information indicative of the transmission destination user and the transmission destination terminal designated with the designation unit to an apparatus that transmits the document to the transmission destination terminal.


