Role-Based Access Control for Application Packages

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing information processing systems lack the ability to set roles within application packages, leading to unauthorized access by users who do not want to use the application package.

Innovation Solution

An information processing system that includes a circuitry for setting roles within application packages, allowing users to be assigned usage authorities based on their allocated roles, thereby permitting or restricting access to the application package.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If application packages are provided to users without role-based access control, then users can access the application package, but unauthorized users can access the application package even when they do not want to use it

Engineering Contradiction:
Improveaccess control reliabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the application package into role-based access control units. Each application package is associated with specific roles (e.g., administrator, user) that define who can access it. The system divides the access control mechanism into separate role definitions, role assignments, and access permission layers, making it possible to control access at multiple levels without requiring complete system redesign

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements preliminary action by pre-defining roles and their associated permissions before users access the application package. Role-based access control policies are established in advance, and users are assigned to predefined roles rather than requiring on-demand permission configuration. This preliminary setup ensures that only authorized users can access the application package while simplifying the actual access control process

Inventive Principle:
Principle #10Preliminary action

2Reliability

If role-based access control is implemented for application packages, then unauthorized access is prevented, but the system complexity increases

Engineering Contradiction:
Improveaccess control reliabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies universality by creating a role-based access control system that can be applied across multiple application packages and user types. The same role management framework serves different purposes: controlling access to various application packages, managing different user roles (administrator, user, guest), and providing consistent access control policies throughout the system. This multi-functional approach reduces overall system complexity despite the added functionality

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent introduces roles as intermediary elements between users and application packages. Instead of directly managing complex access permissions for each user-package combination, the system uses roles as mediators. Users are assigned to roles, and roles automatically determine which application packages they can access. This intermediary layer simplifies the access control logic while maintaining reliable security

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11595394B2Information processing system, apparatus, and method for setting a role in an application package
Publication Date: 2023.02.28 RICOH CO LTD
  • US11595394B2 patent drawing
  • US11595394B2 patent drawing
  • US11595394B2 patent drawing

AI summary

At least one information processing apparatus includes a circuitry that: receives, as a package management unit, a setting of a role, which can assign a usage authority of an application package containing at least one application, with respect to the application package, and permits or restricts, as a user management unit, a user to use the application package in conformity with the role, which is allocated to the user of the application, and the role, which is set in the application package.