Information Processing Device Organization Policy Application

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In a scenario where multiple organizations with different information protection policies share an information processing device, it is challenging to apply the appropriate information protection policy to a user who cannot be identified.

Innovation Solution

An information processing device is designed with a specifying unit to identify the organization a user belongs to and an application unit to apply the corresponding information protection policy, including modules for user authentication, policy extraction, and application, ensuring that users access the device according to their affiliated organization's security standards.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If multiple organizations share an information processing device, then device utilization efficiency is improved, but it becomes difficult to apply appropriate information protection policies for unidentified users

Engineering Contradiction:
Improvedevice utilization efficiencyVSAvoidinformation protection policy application
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent applies preliminary action by determining the organization affiliation of a user before the user is fully identified. The specifying unit identifies the organization to which the user belongs prior to authentication, allowing the application unit to pre-apply the appropriate information protection policy. This ensures that security policies are enforced from the moment the user accesses the device, even before complete user identification occurs, thus resolving the contradiction between shared device access and policy enforcement.

Inventive Principle:
Principle #10Preliminary action

2Measurement precision

If user identification is required before policy application, then policy accuracy is improved, but user access speed deteriorates

Engineering Contradiction:
Improvepolicy application accuracyVSAvoiduser access time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs organization specification before complete user identification, extracting organizational information from available data (such as email domain or user profile) prior to authentication. This preliminary organization determination allows the appropriate information protection policy to be applied immediately, reducing access time while maintaining policy accuracy.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The user identification process is segmented into two independent stages: organization specification and user authentication. The specifying unit handles organization identification separately from the authentication unit's user verification. This segmentation allows organization-based policy application to occur in parallel with user authentication, improving access speed without compromising policy accuracy.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11455408B2Information processing device and non-transitory computer readable medium
Publication Date: 2022.09.27 FUJIFILM BUSINESS INNOVATION CORP
  • US11455408B2 patent drawing
  • US11455408B2 patent drawing
  • US11455408B2 patent drawing

AI summary

An information processing device is shared by multiple organizations having different information protection policies, the information processing device including: a specifying unit that specifies an organization to which a user using the information processing device belongs, before identifying the user; and an application unit that applies an information protection policy corresponding to the organization specified by the specifying unit, to the information processing device.