Tenant-Aware Device Access Control via Group Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cloud-based management systems lack efficient control over device usage across multiple tenant systems, leading to inconsistent access and usage permissions, particularly when integrating or dividing these systems.

Innovation Solution

A management apparatus with user and device information management units, along with a controller, that associates user identification information with group memberships and device permissions, enabling controlled device usage based on group affiliations, facilitating seamless integration and division of tenant systems while maintaining access permissions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If cloud-based management systems are used to manage devices across multiple tenant systems, then device accessibility and service flexibility are improved, but control consistency and permission management become problematic during system integration or division

Engineering Contradiction:
Improvedevice accessibilityVSAvoidcontrol consistency
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The management system is segmented into multiple tenant systems, each with independent group and permission management. This allows each tenant system to maintain its own access control policies while being part of the larger cloud-based management infrastructure, resolving the contradiction between flexibility and consistency.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Group information and device permissions are pre-configured and stored in the management apparatus before system integration or division occurs. This preliminary setup ensures that when tenant systems are integrated or divided, the access control relationships are already established and maintained consistently across the reorganized structure.

Inventive Principle:
Principle #10Preliminary action

2Adaptability or versatility

If device permissions are managed centrally in cloud-based systems, then service flexibility is improved, but control over device usage across multiple tenant systems becomes inconsistent

Engineering Contradiction:
Improveservice flexibilityVSAvoidpermission management
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

Permission management is segmented by tenant system and group, allowing each tenant to independently manage device permissions for their specific users and groups. This segmentation maintains service flexibility at the cloud level while simplifying permission management at the tenant level through localized control.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system adds a tenant system dimension to the traditional user-device permission model. Permissions are now managed in three dimensions: tenant system, group, and device. This multi-dimensional approach allows flexible service delivery while simplifying operation through structured, hierarchical permission control.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Reliability

If group information is managed in association with user identification, then user access control is improved, but system complexity increases during tenant system integration or division

Engineering Contradiction:
Improveuser access controlVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Group information is segmented by tenant system, with each tenant maintaining its own group definitions and user associations. This segmentation maintains reliable user access control within each tenant while reducing overall system complexity during integration or division, as each tenant's group structure remains independent and manageable.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The group management mechanism serves multiple functions: it controls user access to devices, defines permission scopes, and maintains user relationships across tenant systems. This universal group structure reduces complexity by providing a single, consistent mechanism that handles multiple access control requirements simultaneously.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9430171B2Management apparatus, management method, non-transitory computer readable medium, and information processing system
Publication Date: 2016.08.30 FUJIFILM BUSINESS INNOVATION CORP
  • US9430171B2 patent drawing
  • US9430171B2 patent drawing
  • US9430171B2 patent drawing

AI summary

A management apparatus includes a user information management unit, a device information management unit, and a controller. The user information management unit manages information about groups to which individual users belong, in association with user identification information identifying the users. The device information management unit manages, for one device or each of plural devices, information about a main group to which the device belongs and information about a sub-group for which use of the device is permitted, in association with each other. The controller controls, when accepting a request for using a device from an information terminal, use of the device in accordance with whether or not information about a group managed in association with user identification information of a user who operates the information terminal is included in information about the main group or sub-group managed in association with the device.