Hierarchical Region Access Control for Devices and Tasks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing device management systems fail to effectively manage devices belonging to no region or tasks spanning multiple regions, leading to administrative burdens due to the need for special operations and access control.

Innovation Solution

A device management apparatus that sets attributes for regions, users, devices, and tasks, and controls access based on these settings, allowing for efficient management across hierarchical regions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If hierarchical region construction is used for access control, then access security is improved, but device complexity and administrative burden increase due to special operations required for devices outside hierarchy

Engineering Contradiction:
Improveaccess securityVSAvoidadministrative burden
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The region management system is designed to universally handle both hierarchical regions and non-hierarchical devices through a unified access control mechanism. The management apparatus evaluates access requests by comparing user's home region with target device's region using consistent rules, whether the device belongs to a hierarchical region or not, eliminating the need for special exception handling operations.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system segments the access control evaluation into distinct components: identifying the user's home region, identifying the target device's region, comparing regional relationships, and determining access permission. This segmentation allows the system to handle hierarchical and non-hierarchical cases through the same structured process, reducing administrative complexity.

Inventive Principle:
Principle #1Segmentation

2Reliability

If special operations are required for devices outside hierarchy, then access control precision is improved, but ease of operation deteriorates

Engineering Contradiction:
Improveaccess control precisionVSAvoidease of operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The management apparatus automatically performs region comparison and access permission determination without requiring administrator intervention for special operations. The system self-evaluates whether a user can access a device by comparing their home region with the device's region, handling both hierarchical and non-hierarchical cases through automated rule-based evaluation.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system pre-establishes access control rules that define how users can access devices in different regional relationships. These rules are configured in advance to handle various scenarios including hierarchical regions, non-hierarchical devices, and cross-region access, so that no special operations are needed during actual access requests.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If region-based access control is implemented, then security is improved, but productivity decreases due to additional administrative overhead

Engineering Contradiction:
ImprovesecurityVSAvoidproductivity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The automated region comparison and access permission determination system eliminates the need for administrators to manually evaluate each access request. The management apparatus independently performs security evaluations by comparing user home regions with target device regions, maintaining security while eliminating administrative overhead.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12381775B2Device management apparatus, control method, and nontransitory computer-readable storage medium
Publication Date: 2025.08.05 CANON KK
  • US12381775B2 patent drawing
  • US12381775B2 patent drawing
  • US12381775B2 patent drawing

AI summary

A device management application sets an attribute for each of a plurality of regions, sets a region to a user, sets a region to a device and a device group, sets a region to a task defining an operation for a management target device, and controls access of a user to the device, the device group, and the task in accordance with a set region.