Document Signing Using Access Point Certificate for Network Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Confidential information leakage occurs when authenticated users copy and take documents from a mobile terminal outside a company, as existing security measures relying on digital certificates and passwords are insufficient in ensuring access control beyond the company's premises.
Innovation Solution
An information processing apparatus with a signing unit and obtaining units that utilize digital certificates to sign documents and verify the authenticity of access requests, ensuring that documents are only displayed if the fingerprints of the signing certificate and the access point certificate match, thereby preventing unauthorized access outside the company's network.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If digital certificate and password authentication is used for document access control, then access security within the company is improved, but documents can still be copied and taken outside the company leading to information leakage
Solution Approach 1:
The system performs preliminary actions by signing the document with the access point's certificate before the document leaves the company network. This preliminary signing binds the document to the company's network environment, enabling later verification of whether the document is being accessed within the authorized network boundaries.
Solution Approach 2:
The system implements feedback by verifying whether the mobile terminal is currently connected to the same access point whose certificate was used to sign the document. This feedback mechanism continuously monitors the access environment and prevents document access when the terminal is outside the company network, thereby preventing information leakage.
2Reliability
If document access is restricted to company network only, then confidential information security is improved, but user flexibility and mobility are reduced
Solution Approach 1:
The system enables self-service by automatically performing certificate-based signing when documents are obtained within the company network and automatically verifying the access environment before allowing document access. This eliminates the need for manual security checks while maintaining strict access control, preserving user mobility without compromising security.
Solution Approach 2:
The system replaces mechanical physical access control with electronic certificate-based verification. Instead of requiring physical presence in the company premises, the system uses digital certificates to verify network location, enabling secure remote access within the company network while preventing access outside the network.
3Reliability
If certificate-based signing and verification is implemented, then document access control outside company network is improved, but system complexity increases
Solution Approach 1:
The system achieves universality by using the access point's certificate for multiple purposes: it serves as both the network authentication credential and the document signing credential. This multi-functionality eliminates the need for separate document signing infrastructure, reducing system complexity while maintaining strong access control.
Solution Approach 2:
The access point certificate acts as an intermediary that bridges network authentication and document access control. By using the same certificate for both network access and document signing, the system creates a unified security mechanism that simplifies the overall architecture while ensuring that document access is tightly coupled with network access control.
Data Source
AI summary
An information processing apparatus includes a signing unit and first and second obtaining units. The signing unit signs a document by using a certificate used for connecting to an access point. The document is obtained via the access point. The first obtaining unit obtains, in response to an access request to access the signed document, identification information concerning the certificate used for signing the signed document. The second obtaining unit obtains identification information concerning a certificate used for connecting to an access point when the access request is received. The display controller performs control so that the sighed document will be displayed if the identification information obtained by the first obtaining unit and the identification information obtained by the second obtaining unit coincide with each other.


