Dynamic Security Policy Management for Multi-Function Peripherals

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The diversification of office environments due to teleworking and the use of satellite or rental offices leads to varying network environments for information processing apparatuses, making it challenging to apply a suitable security policy, as existing techniques fail to adapt security settings in real-time with changes in network connections, such as IP address changes from private to global addresses, increasing the risk of unauthorized access.

Innovation Solution

An information processing system that includes a specifying unit to identify the network environment, a selection unit to choose a suitable security policy, and a delivery unit to apply the selected policy to the information processing apparatus, ensuring the security policy is updated based on the current network environment, using a management server and multi-function peripherals as examples.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a fixed security policy is applied to information processing apparatuses, then the security setting is simple and easy to manage, but the security policy becomes unsuitable when network environment changes occur

Engineering Contradiction:
Improvesecurity policy adaptabilityVSAvoidsecurity policy management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The security policy is made dynamic by automatically adjusting it according to detected network environment changes. The system monitors network parameters (such as IP address type, network topology) and dynamically updates the security policy settings to match the current environment, transitioning from a static to a dynamic security management approach.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system implements feedback mechanisms where network environment information is continuously detected and fed back to the security policy management unit. Based on this feedback, the system automatically adjusts security policies, creating a closed-loop control system that adapts to changing network conditions without manual intervention.

Inventive Principle:
Principle #23Feedback

2Reliability

If individual security settings are adjusted for each information processing apparatus, then each apparatus is protected according to its specific environment, but the management workload increases significantly

Engineering Contradiction:
Improvesecurity protection effectivenessVSAvoidsecurity management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system creates a universal security policy management approach where a single management apparatus can control multiple information processing apparatuses. The management server detects network environments and automatically applies appropriate security policies to various apparatuses, eliminating the need for individual manual configuration of each device while maintaining environment-specific security settings.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The information processing apparatuses perform self-configuration by automatically detecting their network environment and requesting appropriate security policies from the management server. This self-service mechanism eliminates manual security configuration tasks for administrators while ensuring each apparatus receives customized security settings suited to its specific network conditions.

Inventive Principle:
Principle #25Self-service

3Object-affected harmful factors

If security policies are not updated when network environment changes, then the management process is simple, but the risk of unauthorized access increases

Engineering Contradiction:
Improveunauthorized access riskVSAvoidsecurity policy update automation
Core Design Contradiction:
Object-affected harmful factorsVSExtent of automation

Solution Approach 1:

The system takes preliminary action by detecting network environment changes before security threats can exploit vulnerabilities. When network changes are detected (such as IP address reconfiguration or network topology changes), the system proactively updates security policies in advance, preventing potential unauthorized access rather than responding after security breaches occur.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The security policy management system operates continuously, maintaining constant monitoring of network environments and continuously updating security policies as needed. This continuous action ensures that security measures are always current and effective, eliminating gaps in protection that could allow unauthorized access.

Inventive Principle:
Principle #20Continuity of useful action

Data Source

PatentUS12159071B2Information processing system, information processing apparatus, and control method for setting a security policy to be managed depending on circumstances at different times
Publication Date: 2024.12.03 CANON KK
  • US12159071B2 patent drawing
  • US12159071B2 patent drawing
  • US12159071B2 patent drawing

AI summary

An information processing system includes a management server and a multi-function peripheral (MFP). The management server specifies an environment of a network to which the MFP is connected, selects a security policy associated with the specified environment of the network, and delivers the security policy to the MFP. The MFP receives the security policy associated with the environment of the connected network from the management server, and applies the security policy.