IP Address Whitelist Management via Elapsed Time Tracking

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In facilities with multiple users, existing IP address filtering systems struggle to efficiently distinguish and invalidate permissions for terminals that are no longer in use, leading to increased administrative burden and security risks due to the difficulty in managing a large number of registered IP addresses.

Innovation Solution

An information apparatus, such as a multifunction peripheral, records communication status and elapsed time for each IP address, extracts addresses that meet predetermined conditions, and determines whether to restrict communication or delete them from the whitelist, allowing for timely invalidation of permissions and enhanced security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If address filtering function is used to permit specific terminals, then unauthorized access is prevented, but it becomes difficult to distinguish active from inactive terminals over time

Engineering Contradiction:
Improveaccess control reliabilityVSAvoidterminal status detection difficulty
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The system performs preliminary actions by establishing elapsed time conditions in advance for each communication counterpart. These conditions are set before the terminal actually becomes inactive, enabling the system to proactively identify and restrict permissions based on predetermined time thresholds rather than waiting for manual review.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements continuous feedback by measuring elapsed time since last communication and comparing it against stored conditions. This automatic feedback mechanism triggers permission restriction when thresholds are exceeded, eliminating the need for manual tracking and ensuring timely updates to access control status.

Inventive Principle:
Principle #23Feedback

2Reliability

If manual management of IP address permissions is performed, then access control is maintained, but administrative burden increases with large numbers of users

Engineering Contradiction:
Improveaccess controlVSAvoidadministrative operation ease
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system enables self-service by automatically measuring elapsed time and comparing it against stored conditions for each communication counterpart. This automation allows the system to manage its own access control permissions without requiring continuous manual intervention, significantly reducing administrative burden while maintaining security.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system changes the management parameter from manual IP address tracking to automatic elapsed time measurement. By storing and comparing time-based parameters rather than manually managing permission lists, the system transforms a labor-intensive process into an automated parameter-driven control mechanism.

Inventive Principle:
Principle #35Parameter changes

3Adaptability or versatility

If permission is given to multiple terminals for temporary use, then user accessibility is improved, but security risks increase due to difficulty in invalidating permissions timely

Engineering Contradiction:
Improveterminal accessibilityVSAvoidsecurity risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system establishes elapsed time conditions in advance for each communication counterpart before they become inactive. This preliminary setup enables automatic detection and restriction of permissions when terminals exceed the specified time thresholds, ensuring timely invalidation without manual intervention.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system continuously measures elapsed time since last communication and provides automatic feedback when thresholds are exceeded. This real-time feedback mechanism triggers immediate permission restriction, eliminating security delays while maintaining broad accessibility during active periods.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS9940080B2Information apparatus, communication management method, and non-transitory computer-readable medium
Publication Date: 2018.04.10 RICOH CO LTD
  • US9940080B2 patent drawing
  • US9940080B2 patent drawing
  • US9940080B2 patent drawing

AI summary

An information apparatus to communicate with one or more communication counterparts includes a memory and circuitry. The memory is configured to store an elapsed time condition in association with identification information for each of the one or more communication counterparts. The circuitry is configured to measure an elapsed time from the last time when communication took place with the communication counterpart for each of the one or more communication counterparts. The circuitry is further configured to extract identification information for which the measured elapsed time satisfies the elapsed time condition stored in the memory. The circuitry is further configured to determine whether to restrict communications between the information apparatus and at least one of the communication counterparts corresponding to the extracted identification information.