IP Address Whitelist Management via Elapsed Time Tracking
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In facilities with multiple users, existing IP address filtering systems struggle to efficiently distinguish and invalidate permissions for terminals that are no longer in use, leading to increased administrative burden and security risks due to the difficulty in managing a large number of registered IP addresses.
Innovation Solution
An information apparatus, such as a multifunction peripheral, records communication status and elapsed time for each IP address, extracts addresses that meet predetermined conditions, and determines whether to restrict communication or delete them from the whitelist, allowing for timely invalidation of permissions and enhanced security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If address filtering function is used to permit specific terminals, then unauthorized access is prevented, but it becomes difficult to distinguish active from inactive terminals over time
Solution Approach 1:
The system performs preliminary actions by establishing elapsed time conditions in advance for each communication counterpart. These conditions are set before the terminal actually becomes inactive, enabling the system to proactively identify and restrict permissions based on predetermined time thresholds rather than waiting for manual review.
Solution Approach 2:
The system implements continuous feedback by measuring elapsed time since last communication and comparing it against stored conditions. This automatic feedback mechanism triggers permission restriction when thresholds are exceeded, eliminating the need for manual tracking and ensuring timely updates to access control status.
2Reliability
If manual management of IP address permissions is performed, then access control is maintained, but administrative burden increases with large numbers of users
Solution Approach 1:
The system enables self-service by automatically measuring elapsed time and comparing it against stored conditions for each communication counterpart. This automation allows the system to manage its own access control permissions without requiring continuous manual intervention, significantly reducing administrative burden while maintaining security.
Solution Approach 2:
The system changes the management parameter from manual IP address tracking to automatic elapsed time measurement. By storing and comparing time-based parameters rather than manually managing permission lists, the system transforms a labor-intensive process into an automated parameter-driven control mechanism.
3Adaptability or versatility
If permission is given to multiple terminals for temporary use, then user accessibility is improved, but security risks increase due to difficulty in invalidating permissions timely
Solution Approach 1:
The system establishes elapsed time conditions in advance for each communication counterpart before they become inactive. This preliminary setup enables automatic detection and restriction of permissions when terminals exceed the specified time thresholds, ensuring timely invalidation without manual intervention.
Solution Approach 2:
The system continuously measures elapsed time since last communication and provides automatic feedback when thresholds are exceeded. This real-time feedback mechanism triggers immediate permission restriction, eliminating security delays while maintaining broad accessibility during active periods.
Data Source
AI summary
An information apparatus to communicate with one or more communication counterparts includes a memory and circuitry. The memory is configured to store an elapsed time condition in association with identification information for each of the one or more communication counterparts. The circuitry is configured to measure an elapsed time from the last time when communication took place with the communication counterpart for each of the one or more communication counterparts. The circuitry is further configured to extract identification information for which the measured elapsed time satisfies the elapsed time condition stored in the memory. The circuitry is further configured to determine whether to restrict communications between the information apparatus and at least one of the communication counterparts corresponding to the extracted identification information.


