Dynamic QR Code Access for Secure File Sharing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional file sharing systems require pre-applying access rights, which complicates security when sharing files outside the initial access context, particularly in information storage systems.
Innovation Solution
An information storage system and method that generates and manages access information dynamically, allowing restricted access to a storage area by one information processing device to be shared with another, using a QR code-based access key that is valid for a limited time, ensuring secure and controlled file sharing.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If access rights are applied in advance to files or folders, then file sharing among multiple users is enabled, but security is compromised when files need to be shared outside the initial access context
Solution Approach 1:
The patent implements dynamic access control by generating temporary access information (QR codes) that are valid only for specific time periods and specific target devices. This allows the system to adapt access rights dynamically based on the sharing context, rather than relying on static pre-configured access rights. The access information includes expiration timestamps and device-specific identifiers, enabling flexible and secure file sharing outside the initial access context.
Solution Approach 2:
The patent introduces an intermediary access information generation unit that acts as a mediator between the file server and external devices. This unit generates temporary access information (QR codes) that bridges the gap between restricted file storage and external access needs. The QR code serves as an intermediary credential that enables secure temporary access without compromising the underlying security model of the file system.
2Adaptability or versatility
If pre-configured access rights are used for file sharing, then sharing functionality is provided, but the system becomes complex and requires advance setup
Solution Approach 1:
The patent implements a self-service file sharing mechanism where the file server automatically generates temporary access information (QR codes) in response to sharing requests. Users simply need to initiate a share request, and the system automatically creates the appropriate access credentials without requiring manual configuration of access rights. This eliminates the complexity of advance setup while maintaining flexible sharing capabilities.
Solution Approach 2:
The patent uses QR codes as a simplified copyable representation of complex access rights. Instead of configuring detailed access control lists and permissions, the system generates a QR code that encapsulates all necessary access information. This QR code can be easily copied and transferred to the target device, replacing complex configuration procedures with a simple scanning operation.
3Reliability
If access information is generated dynamically with time limits, then security is enhanced, but additional processing is required
Solution Approach 1:
The patent replaces complex mechanical access control mechanisms with optical recognition technology. Instead of configuring and managing complex access right settings, the system uses QR code generation and recognition. The file server generates QR codes containing encoded access information, and the terminal device uses its camera to scan and automatically decode the QR code. This substitution of optical recognition for manual configuration significantly reduces processing complexity while maintaining enhanced security through time-limited access information.
Data Source
AI summary
An information storage system including information processing devices; an information storage device connected to the information processing devices; an access information generating unit configured to generate, based on a request from a first information processing device, access information for accessing a storage area in the information storage device to which access is restricted from the information processing devices other than the first information processing device; a display unit configured to cause the first information processing device to display the access information; a sending unit configured to cause a second information processing device to acquire the access information displayed on the first information processing device and to send the access information to the information storage device; and an access unit configured to cause the information storage device to allow the second information processing device to access the storage area based on the access information that has been sent.


