Multi-functional Device Access Control via Segmented Permissions
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing multi-functional devices lack effective functionality in limiting user access to various functions, particularly when requests are made without proper identification information, leading to inconsistent and insecure usage.
Innovation Solution
A multi-functional device with a processor and memory that stores user information and permission tables, allowing it to differentiate between individual and general user permissions, and execute functions based on received requests from terminal apparatuses with or without driver programs, ensuring secure and appropriate function execution.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If the device uses a simple general permission system for function access, then ease of operation is improved, but security and access control precision deteriorate
Solution Approach 1:
The permission system is segmented into two distinct levels: general user information applicable to all users, and individual user information for specific users. This segmentation allows the system to maintain simple general permissions while adding targeted individual control where needed, resolving the contradiction between ease of operation and security.
Solution Approach 2:
The patent applies different permission control qualities to different user scenarios. General permission information provides uniform access control for all users (simple operation), while individual permission information provides customized control for specific users (enhanced security). This local differentiation resolves the contradiction by applying the appropriate level of control complexity only where necessary.
2Reliability
If the device requires individual identification information for all function requests, then security is improved, but device complexity and ease of operation worsen
Solution Approach 1:
The system implements partial individual identification requirements rather than requiring it for all function requests. Individual identification is only required when individual permission information exists and applies to the specific function being requested. For other cases, general permission information suffices, reducing the overall complexity while maintaining security where needed.
Solution Approach 2:
The permission verification process is segmented into two pathways: one for general users using general permission information, and another for individual users requiring individual identification. This segmentation reduces complexity by allowing most requests to follow the simpler general pathway while providing the individual identification pathway only when necessary for security.
3Adaptability or versatility
If the device supports both driver program and non-driver program requests, then adaptability is improved, but consistency in permission control deteriorates
Solution Approach 1:
The patent creates a universal permission control mechanism that handles both driver program requests and non-driver program requests through the same dual-layer permission system. The request processing logic universally checks general permission information first, then conditionally checks individual permission information, ensuring consistent control across different request types while maintaining adaptability to various user scenarios.
Solution Approach 2:
Instead of treating driver and non-driver requests differently with separate permission systems, the patent inverts the approach by having both request types go through the same permission verification process. The system checks general permissions for all requests, then inverts the normal flow by optionally requiring individual identification based on the request type and stored individual permission information, ensuring consistency while accommodating different access methods.
Data Source
AI summary
A multi-functional device configured to receive a function execution request transmitted from a terminal device without using a driver program, transmit a relation information request for requesting transmission of user relation information to the terminal apparatus, in a case where the function execution request not including individual relation information relating to individual identification information is received from the terminal apparatus, and control a specific function engine of the multi-functional device to execute a specific function, in a case where the function execution request including individual relation information relating to individual identification information is received from the terminal apparatus in response to the transmitting of the relation information request to the terminal apparatus and on condition that individual permission information associated with the individual identification information in a table indicates that use of the specific function is permitted.


