Dual-Controller Access Authority Mediator

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In existing information processing systems, users may redundantly have authority to use the same resource, leading to inefficient resource management and potential security vulnerabilities.

Innovation Solution

The system incorporates a dual-controller architecture with independent management of user access and authority, where a second controller identifies and manages user roles across multiple tenants to prevent redundant authority assignments, ensuring accurate and secure resource allocation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If multiple independent controllers manage user access to resources, then access control flexibility and management autonomy are improved, but redundant authority assignments occur leading to resource management inefficiency

Engineering Contradiction:
Improveaccess control flexibilityVSAvoidresource management efficiency
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The patent introduces an identifier (acting as an intermediary) that links authority assignments across multiple independent controllers. When the second controller assigns authority to a user, the identifier enables detection of existing authority assignments in the first manager, preventing redundant assignments while preserving the independence of each controller.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements feedback mechanisms where the second controller queries the first manager through the identifier to check for existing authority assignments before granting new authority. This feedback loop ensures that redundant authority assignments are detected and prevented, maintaining resource management efficiency.

Inventive Principle:
Principle #23Feedback

2Extent of automation

If multiple independent controllers manage user access to resources, then system autonomy and distributed control are improved, but security vulnerabilities arise from redundant authority assignments

Engineering Contradiction:
Improvedistributed control autonomyVSAvoidsecurity
Core Design Contradiction:
Extent of automationVSReliability

Solution Approach 1:

The identifier serves as a security intermediary that enables independent controllers to verify authority assignments across the system. By querying through the identifier, controllers can detect redundant authorities that would create security vulnerabilities, maintaining both distributed autonomy and system security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary checks before granting authority by querying the first manager through the identifier. This preliminary anti-action prevents redundant authority assignments from occurring in the first place, addressing security vulnerabilities proactively rather than reactively.

Inventive Principle:
Principle #9Preliminary anti-action

3Device complexity

If independent controllers separately manage user authority, then controller independence and modular architecture are improved, but authority redundancy occurs across controllers

Engineering Contradiction:
Improvemodular architectureVSAvoidauthority assignments
Core Design Contradiction:
Device complexityVSQuantity of substance

Solution Approach 1:

The identifier acts as a mediator that connects the modular controllers while enabling detection of authority redundancy. It allows each controller to maintain its independence and modular architecture while preventing the accumulation of redundant authority assignments across the distributed system.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Ease of operation

If redundant authority assignments are allowed, then user access flexibility is improved, but resource management precision deteriorates

Engineering Contradiction:
Improveuser access flexibilityVSAvoidresource allocation accuracy
Core Design Contradiction:
Ease of operationVSMeasurement precision

Solution Approach 1:

The system uses feedback through the identifier to detect existing authority assignments before granting new ones. This feedback mechanism maintains user access flexibility by allowing multiple authority assignments while preventing redundant assignments that would compromise resource allocation accuracy.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11481166B2Information processing system, information processing apparatus for controlling access to resources and functions for managing users allowed to access the resources
Publication Date: 2022.10.25 FUJIFILM BUSINESS INNOVATION CORP
  • US11481166B2 patent drawing
  • US11481166B2 patent drawing
  • US11481166B2 patent drawing

AI summary

An information processing system includes a first controller that controls access to resources on a network based on authority to use the resources, a first manager that registers and manages users who access the resources via the first controller, a second controller that controls, independently of the first controller, access to the resources on the network based on authority to use the resources, a second manager that registers and manages users who access the resources via the second controller, and an identifier that identifies, in response to second authority to use a resource in the second manager being set for a user, first authority of the user to use the resource in the first manager.