Centralized Security Information Update for MFPs
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing security information update systems for Multi Function Peripherals (MFPs) face challenges in managing and updating passwords across multiple devices, leading to potential leaks and complex settings, as well as issues with unauthorized access and delayed updates due to lack of centralized management.
Innovation Solution
A security information management system that includes a hardware processor for authenticating users, updating security information, and setting configurations within MFPs, with a centralized management server to coordinate updates and access permissions, ensuring timely and secure password updates across devices.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a password is changed in one image processing apparatus, then the password is updated in that device, but the password is not changed in other image processing apparatus where the same user does not administer
Solution Approach 1:
The patent merges the password update operations across multiple image processing apparatus by introducing a centralized management server that coordinates password changes. When a password is changed in one device, the management server automatically propagates the update to all other devices in the network, ensuring consistent password security without requiring manual intervention at each device.
Solution Approach 2:
The management server acts as an intermediary between image processing apparatus. It receives password change requests from any authorized device and automatically distributes the updated password information to all other devices, eliminating the need for users to manually update passwords at each individual apparatus.
2Ease of operation
If password is transmitted and received between image scanning devices, then the password can be set in another device, but the password may leak
Solution Approach 1:
The management server serves as a secure intermediary that handles password transmission between devices. Instead of direct peer-to-peer password transmission which risks leakage, the server mediates the exchange by receiving encrypted password data from one device and securely distributing it to authorized devices, thereby preventing password exposure during transmission.
Solution Approach 2:
The system uses encrypted copies of password information rather than transmitting the actual plaintext password. The management server stores and transmits encrypted password data, which can be decrypted only by authorized devices using their secret keys, thus preventing password leakage even if transmission is intercepted.
3Reliability
If usage limitation information is set in each image forming apparatus, then unauthorized access can be limited, but the setting becomes complicated when multiple devices must be configured
Solution Approach 1:
The patent merges the usage limitation management across multiple image forming apparatus by implementing a centralized policy management system. Usage limitation policies are defined once in the management server and automatically applied to all connected devices, eliminating the need to configure each device individually and reducing setting complexity while maintaining security.
Solution Approach 2:
The management server provides universal usage limitation management that works across multiple different image forming apparatus types. A single policy configuration in the server can be applied universally to various devices on the network, simplifying administration while maintaining unauthorized access prevention.
Data Source
AI summary
Each of the plurality of information processing apparatus includes an operation panel, a storage that stores security information, and a hardware processor. The hardware processor registers an administrator, when a user is registered as the administrator, authenticates the user, and when the user is authenticated, executes a first process of updating any of the stored security information, and a second process of setting the information processing apparatus in accordance with an operation by the authenticated user, and when the user is not registered as the administrator and is authenticated as an administrator in communicable another information processing apparatus, executes the first process but not the second process.


