Image Processing Apparatus Network Security Policy Enforcement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods, such as those discussed in Japanese Patent Application Laid-Open No. 2012-146337, fail to prevent changes to setting values in information processing apparatuses via a network that do not conform to security policies, particularly in managing multifunction peripherals (MFPs), allowing unauthorized changes to security settings.

Innovation Solution

An image processing apparatus with a receiving unit for network requests, a determination unit to assess user authority based on received requests, and a control unit that enforces security policy settings to permit or deny changes to setting values, ensuring compliance with security policies by identifying user authority and security policy associations for each setting item.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If authentication based on authentication information is performed, then access control is achieved, but unauthorized changes to setting values conforming to security policies cannot be prevented

Engineering Contradiction:
Improveaccess controlVSAvoidunauthorized changes to setting values
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the access control process into multiple independent verification stages: first verifying authentication information, then checking user authority for write access, and finally validating against security policies. Each stage operates independently to provide comprehensive control, preventing unauthorized changes by breaking down the single authentication step into granular checks.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary actions by pre-defining security policies and user authorities before processing any setting value changes. Authority information and security policy rules are established in advance, allowing the system to proactively prevent unauthorized changes before they occur, rather than reacting after authentication fails.

Inventive Principle:
Principle #10Preliminary action

2Ease of operation

If setting value changes are permitted based on authentication, then operational flexibility is improved, but security policy compliance cannot be ensured

Engineering Contradiction:
Improvesetting value changeVSAvoidsecurity policy compliance
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system implements feedback control by continuously monitoring setting value change requests against pre-defined security policies. When a change request is received, the system checks it against the security policy database and provides immediate feedback by permitting or blocking the change based on compliance, ensuring security rules are enforced while allowing legitimate operations.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The access control system dynamically adjusts permission levels based on the specific setting item being modified and the user's authority. Rather than using static allow/deny rules, the system adapts its response to each request by evaluating the combination of user authority, setting item sensitivity, and security policy requirements, enabling flexible yet secure operation.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS9813574B2Image processing apparatus and information processing method
Publication Date: 2017.11.07 CANON KK
  • US9813574B2 patent drawing
  • US9813574B2 patent drawing
  • US9813574B2 patent drawing

AI summary

An image processing apparatus includes a receiving unit configured to receive a request from an information processing apparatus capable of communicating with the image processing apparatus via a network, a determination unit configured to, based on authority information about user's authority included in the request received by the receiving unit and setting item information for identifying a setting item included in the request, determine whether a user has a write authority on the setting item, and a control unit configured to, in a case where the determination unit determines that the user has the write authority on the setting item, control whether to permit a change of a setting value of the setting item, based on a setting value of security policy information associated with the setting item.