Image Processing Apparatus Security Policy Configuration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional systems lack user-friendliness in changing user modes of multifunction peripherals to maintain compliance with information security policies, requiring administrative intervention and lacking flexibility in settings like switching between 'use SSL' and 'use IPSEC' for encryption.

Innovation Solution

An image processing apparatus with a reception unit for security policy data, an identification unit to determine the operation mode, and a configuration unit to ensure compliance with the information security policy, allowing users to change settings while maintaining policy compliance without administrative intervention.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security policy data is distributed to multifunction peripherals, then information security compliance is improved, but device complexity and ease of operation deteriorate due to vendor-specific setting variations

Engineering Contradiction:
Improveinformation security complianceVSAvoidsetting configuration
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces a conversion unit as an intermediary component that translates vendor-neutral security policy data into vendor-specific user mode settings. This conversion unit acts as a mediator between the universal security requirements and the proprietary implementation details of different multifunction peripheral vendors, automatically handling the translation without requiring administrator intervention for each vendor's specific settings

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system changes the parameter representation from vendor-specific setting parameters to vendor-neutral security policy parameters. By defining security requirements in terms of generic parameters (encryption required, authentication required) rather than vendor-specific parameters (SSL setting, IPSEC setting), the system enables uniform policy distribution across different vendors while maintaining compliance

Inventive Principle:
Principle #35Parameter changes

2Reliability

If administrator configures settings on a multifunction peripheral-by-multifunction peripheral basis, then information security compliance is improved, but loss of time and productivity deteriorate due to enormous administrative effort

Engineering Contradiction:
Improveinformation security complianceVSAvoidadministrative effort
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-defining security policy data with all necessary security requirements before distribution. The conversion unit is pre-configured with knowledge of multiple vendors' user mode settings, enabling it to automatically translate security policies into appropriate settings for any target device without requiring real-time administrator intervention or familiarization with each vendor's specific configuration options

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent creates a universal security policy data format that can be distributed to multifunction peripherals from any vendor. The conversion unit possesses multi-functionality by supporting conversion to multiple different vendors' specific settings formats, enabling a single security policy definition to serve multiple different device types and vendors through automatic translation

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Adaptability or versatility

If user mode settings are made flexible for different vendors, then adaptability is improved, but device complexity increases due to different setting items between vendors

Engineering Contradiction:
Improvevendor compatibilityVSAvoidsetting structure
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the setting configuration into two distinct layers: a vendor-neutral security policy layer that defines security requirements universally, and a vendor-specific user mode layer that handles implementation details. This segmentation allows the system to maintain adaptability across vendors while hiding the complexity of vendor-specific settings from the policy definition process, as the conversion unit automatically handles the mapping between layers

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS9306980B2Image processing apparatus that configures settings of information security policy, method of controlling the same, program, and storage medium
Publication Date: 2016.04.05 CANON KK
  • US9306980B2 patent drawing
  • US9306980B2 patent drawing
  • US9306980B2 patent drawing

AI summary

An image processing apparatus which enables a user to change the user mode while maintaining the state compliant with the information security policy. A network communication section receives security policy data in which information security policy is described from an external apparatus. A CPU identifies an operation mode of the image processing apparatus based on the received security policy. The CPU configures the identified operation mode such that the information security policy is satisfied.