Group-Based Network Assignment for Multi-User Access Changes
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing information processing systems face increased workload when changing the association between a large number of users and networks, particularly in multi-interface configurations, necessitating manual network setting for each user which is burdensome for administrators.
Innovation Solution
An information processing system that specifies a group associated with the user using first association information and then determines a network associated with the group using second association information, reducing the need for manual network setting by administrators.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a network associated with each user by association information is specified as an available network, then network availability for users is ensured, but workload increases when the association between a large number of users and networks is changed
Solution Approach 1:
The patent segments the association information into two separate components: first association information linking users to groups, and second association information linking groups to networks. This segmentation allows independent management of each association type, reducing the overall complexity when changes need to be made. Administrators can modify group-network associations without affecting user-group associations, and vice versa.
Solution Approach 2:
The patent introduces 'groups' as an intermediary layer between users and networks. Instead of direct user-network associations, the system uses user-group-network indirect associations. This intermediary structure simplifies management by allowing administrators to control network access at the group level rather than individually for each user, significantly reducing workload when network associations need to be changed.
2Reliability
If manual network setting is performed for each user in multi-interface configurations, then network security is maintained, but administrator burden increases significantly
Solution Approach 1:
The patent merges network access control settings at the group level rather than requiring individual user configuration. By combining multiple users into groups and assigning network associations to groups, the system maintains security controls while dramatically reducing the number of individual settings administrators must manage. Changes affecting multiple users can be made through a single group association modification.
Solution Approach 2:
The patent creates universal group-level association information that can serve multiple users simultaneously. The group-network second association information acts as a universal configuration that applies to all members of the group, eliminating the need for redundant individual user-network associations. This multi-functional approach maintains security while reducing administrative overhead.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
An information processing system includes one or more processors configured to, in response to a request to use the information processing system by a user, specify a group associated with the user by first association information, and when the group is specified, specify a network associated with the group by second association information separated from the first association information among a plurality of networks connected to the information processing system as a network available to the user.