Dual-Controller Access Authority Mediator
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In existing information processing systems, users may redundantly have authority to use the same resource, leading to inefficient resource management and potential security vulnerabilities.
Innovation Solution
The system incorporates a dual-controller architecture with independent management of user access and authority, where a second controller identifies and manages user roles across multiple tenants to prevent redundant authority assignments, ensuring accurate and secure resource allocation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If multiple independent controllers manage user access to resources, then access control flexibility and management autonomy are improved, but redundant authority assignments occur leading to resource management inefficiency
Solution Approach 1:
The patent introduces an identifier (acting as an intermediary) that links authority assignments across multiple independent controllers. When the second controller assigns authority to a user, the identifier enables detection of existing authority assignments in the first manager, preventing redundant assignments while preserving the independence of each controller.
Solution Approach 2:
The system implements feedback mechanisms where the second controller queries the first manager through the identifier to check for existing authority assignments before granting new authority. This feedback loop ensures that redundant authority assignments are detected and prevented, maintaining resource management efficiency.
2Extent of automation
If multiple independent controllers manage user access to resources, then system autonomy and distributed control are improved, but security vulnerabilities arise from redundant authority assignments
Solution Approach 1:
The identifier serves as a security intermediary that enables independent controllers to verify authority assignments across the system. By querying through the identifier, controllers can detect redundant authorities that would create security vulnerabilities, maintaining both distributed autonomy and system security.
Solution Approach 2:
The system performs preliminary checks before granting authority by querying the first manager through the identifier. This preliminary anti-action prevents redundant authority assignments from occurring in the first place, addressing security vulnerabilities proactively rather than reactively.
3Device complexity
If independent controllers separately manage user authority, then controller independence and modular architecture are improved, but authority redundancy occurs across controllers
Solution Approach 1:
The identifier acts as a mediator that connects the modular controllers while enabling detection of authority redundancy. It allows each controller to maintain its independence and modular architecture while preventing the accumulation of redundant authority assignments across the distributed system.
4Ease of operation
If redundant authority assignments are allowed, then user access flexibility is improved, but resource management precision deteriorates
Solution Approach 1:
The system uses feedback through the identifier to detect existing authority assignments before granting new ones. This feedback mechanism maintains user access flexibility by allowing multiple authority assignments while preventing redundant assignments that would compromise resource allocation accuracy.
Data Source
AI summary
An information processing system includes a first controller that controls access to resources on a network based on authority to use the resources, a first manager that registers and manages users who access the resources via the first controller, a second controller that controls, independently of the first controller, access to the resources on the network based on authority to use the resources, a second manager that registers and manages users who access the resources via the second controller, and an identifier that identifies, in response to second authority to use a resource in the second manager being set for a user, first authority of the user to use the resource in the first manager.


