Network Drive Access Control via Device Proximity
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network drive services lack robust security measures, allowing unauthorized access when user accounts are compromised, as they primarily rely on simple authentication without considering location-based access control.
Innovation Solution
A network drive system that controls access based on location information between communication devices, applying policies to allow or block access based on proximity, using a storage unit for security data, a receiving unit for access requests, a location identification unit to determine device distance, and a policy setting unit to manage access permissions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If simple authentication is used for network drive access, then ease of operation is improved, but security is worsened
Solution Approach 1:
The system changes the authentication parameters from simple credential verification to multi-factor authentication incorporating location information, device identifiers, and proximity-based access control. This resolves the contradiction by maintaining ease of use through automated location-based decisions while significantly improving security through multiple verification parameters.
Solution Approach 2:
The system introduces an intermediary authentication server that mediates between the user's access request and the network drive. This intermediary verifies multiple parameters including location data, device information, and proximity to authorized devices before granting access, thus enhancing security without directly complicating the user's access process.
2Reliability
If location-based access control is implemented, then security is improved, but device complexity is worsened
Solution Approach 1:
The authentication server performs multiple functions including location verification, device identification, proximity calculation, and access decision-making. By consolidating these diverse functions into a single multi-functional system, the patent improves security without proportionally increasing overall system complexity.
Solution Approach 2:
The system automatically performs location-based access control decisions without requiring manual configuration or complex user setup. The authentication server autonomously evaluates location data and device information to make access decisions, reducing the operational complexity despite the enhanced security mechanisms.
3Object-affected harmful factors
If proximity verification is required for access, then data protection is improved, but ease of operation is worsened
Solution Approach 1:
The system performs preliminary authentication checks including location verification and proximity assessment before the user attempts to access the network drive. By pre-validating these parameters, the system prevents unauthorized access while maintaining a simple access process for authorized users who have already been verified.
Solution Approach 2:
The authentication server provides immediate feedback on access decisions based on location and proximity verification. This real-time feedback mechanism allows the system to enforce security policies while maintaining operational simplicity, as users receive instant confirmation of their access status without navigating complex procedures.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
The present invention relates to a method of controlling access to a network drive based on location information on a plurality of communication devices, and a network drive system. A network drive system for controlling access to a network drive based on location information on a communication device according to the present invention includes: a storage unit storing a network drive that stores security data and general data; a receiving unit receiving a request for access to the network drive from a first communication device; a location checking unit checking whether the distance between the first communication device and a second communication device designated as a device for controlling access to the network drive is within a critical value; and a policy setting unit that applies a policy allowing the first communication device to access general data stored in the network drive or applies a policy disallowing the first communication device to access general data stored in the network drive, according to results of the determining by the location checking unit.