Image Forming Apparatus Network Restriction Validation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

When replicating data storage functions across image forming apparatuses connected to different networks, existing systems fail to prevent unintended data transmission to unauthorized networks, leading to potential data security breaches.

Innovation Solution

An image forming apparatus with a reception unit for receiving replication data, a validation unit to check for network restrictions, and a restriction unit to prevent execution if unauthorized networks are detected, ensuring data is stored only in intended networks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If data for replication is received without validation of network restrictions, then the function of storing data can be executed freely, but data may be transmitted to unauthorized networks causing security breaches

Engineering Contradiction:
Improvedata securityVSAvoidfunction execution freedom
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The validation unit validates restriction information for controlling execution of the function before the function is executed. This preliminary validation ensures that network restrictions are checked and enforced prior to data storage operations, preventing unauthorized network transmission while allowing legitimate operations to proceed without interruption.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The validation unit acts as an intermediary between the reception unit and the execution unit. It receives replication data, validates network restrictions, and only permits execution if the validation succeeds. This intermediary mechanism balances security requirements with operational freedom by filtering out unauthorized operations while allowing authorized ones.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If validation of restriction information is performed during data replication, then data transmission to unauthorized networks is prevented, but additional validation steps increase processing time

Engineering Contradiction:
Improvenetwork authorization controlVSAvoiddata replication processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

Restriction information is validated during the data reception phase before actual data processing begins. By performing validation preliminarily, the system avoids rework and ensures that only authorized replication operations proceed, minimizing overall processing time while maintaining security.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If restriction information is validated for every replication operation, then network security is maintained, but the complexity of the replication process increases

Engineering Contradiction:
Improvenetwork securityVSAvoidreplication process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The validation unit serves as a dedicated intermediary component that handles restriction information validation. By isolating the validation logic in a separate unit, the main replication process remains simple while security checks are performed systematically. This modular approach manages complexity by distributing functions across specialized components.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Adaptability or versatility

If the confidential box with the same identifier is used as it is during replication, then data storage function is maintained, but data may be transmitted to unintended networks

Engineering Contradiction:
Improvedata storage function continuityVSAvoidunintended data transmission
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The validation unit validates network restrictions associated with the confidential box identifier before data replication occurs. This preliminary validation ensures that even when using existing confidential box identifiers, the system checks whether the associated network is authorized, preventing unintended data transmission while maintaining storage function continuity.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The validation process provides feedback on whether the network associated with the confidential box identifier is authorized for data transmission. This feedback mechanism allows the system to maintain adaptability by using existing identifiers while preventing harmful effects through network authorization verification.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11172090B2Image forming apparatus and non-transitory computer readable medium for restricting execution of function based on validated restriction information
Publication Date: 2021.11.09 FUJIFILM BUSINESS INNOVATION CORP
  • US11172090B2 patent drawing
  • US11172090B2 patent drawing
  • US11172090B2 patent drawing

AI summary

An image forming apparatus includes: a reception unit that receives, from another apparatus, data for replication of a function of storing data in a preset storage area; a validation unit that validates restriction information for controlling execution of the function if the data for replication received by the reception unit includes information indicating that plural networks are set in the storage area in which the data is to be stored by the function; and a restriction unit that restricts execution of the function if the execution of the function is instructed and the restriction information is validated.