Thin Client System Location-Based Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional thin client systems face security risks due to the potential for confidential information leakage when user terminals, such as laptops, are used outside secure environments, as they may be accessed or stolen, leading to unauthorized viewing or theft of sensitive data.

Innovation Solution

A thin client system that includes a reception unit for user ID and terminal information, an extraction unit for security policy information based on terminal data, an allocation unit for virtualizing client terminal resources, and an access control unit that restricts access to resources according to the extracted policy information, ensuring enhanced security by determining access rights based on user location, terminal type, and usage conditions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a laptop PC is used as a client terminal that can be carried out of the company office, then mobility and ease of operation are improved, but security risk increases due to potential over-the-shoulder hacking or theft

Engineering Contradiction:
ImprovemobilityVSAvoidsecurity risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system dynamically adjusts security policies based on the terminal's current location. When the laptop is detected to be outside the company premises, the system automatically changes security settings to restrict access to confidential information, thereby adapting security measures to the changing operational context and location-based risks

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system continuously monitors the terminal's location through GPS or other positioning mechanisms and uses this feedback to automatically adjust security policies. This closed-loop control ensures that security measures are constantly updated based on real-time location information, maintaining security while allowing mobility

Inventive Principle:
Principle #23Feedback

2Object-affected harmful factors

If security policies are dynamically adjusted based on location, then security is improved, but system complexity increases due to additional monitoring and control mechanisms

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The server performs multiple functions: it virtualizes client terminals, manages security policies, and monitors terminal locations. By consolidating these functions in a single system, the patent avoids the need for separate dedicated devices for each function, thereby managing complexity while achieving comprehensive security control

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Object-affected harmful factors

If virtual machine activation is controlled based on current position, then security is improved, but loss of time occurs due to activation and stoppage operations

Engineering Contradiction:
ImprovesecurityVSAvoidactivation and stoppage time
Core Design Contradiction:
Object-affected harmful factorsVSLoss of time

Solution Approach 1:

The system maintains continuous monitoring of terminal location and keeps the virtual machine in a ready state with security policies pre-configured. When the terminal returns to the company premises, activation occurs rapidly without full shutdown, reducing the time loss while maintaining security during external locations

Inventive Principle:
Principle #20Continuity of useful action

Data Source

PatentEP3623944B1Thin client system, and access control method and access control program for thin client system
Publication Date: 2023.08.09 NEC CORP
  • EP3623944B1 patent drawingFigure 1
  • EP3623944B1 patent drawingFigure 2
  • EP3623944B1 patent drawingFigure 3

AI summary

To heighten security in a thin client system, the thin client system includes: a communication unit 21 that receives a user ID and terminal information including at least current position information from a client terminal 10; a policy information extraction unit 22 that extracts policy information relating to a security policy stored in association with the terminal information received by the communication unit 21 on the basis of the terminal information; a virtual machine allocation unit 32 that allocates a virtual machine virtualizing an environment of the client terminal 10 to a server device 30 on the basis of the user ID received from the client terminal 10; and an access control unit 33 that restricts access to the virtual machine allocated by the virtual machine allocation unit 32 on the basis of the policy information extracted by the policy information extraction unit 22.