Information Processing System Network Port Security Mode Transition
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In an information processing system operating in a security mode with restricted network ports, ensuring security while configuring settings for newly introduced devices is challenging, as unconditional opening of network ports can compromise security.
Innovation Solution
The system includes a first information processing device with a restricted network port that shifts to a setting mode, allowing the duplication of settings to a second information processing device via an opened network port, and then returns to the security mode.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If network ports are opened for configuring settings of newly introduced devices, then ease of operation is improved, but security is worsened
Solution Approach 1:
The network port dynamically changes its state between restricted and opened based on operational context. During device configuration, the port transitions from a restricted state to an opened state temporarily, then returns to restricted state after configuration completes. This dynamic state management allows the system to adapt security levels according to operational needs, resolving the contradiction between ease of configuration and security maintenance.
2Object-affected harmful factors
If network ports remain restricted to ensure security, then security is improved, but ease of operation is worsened
Solution Approach 1:
Before device configuration begins, the system preliminarily opens the network port from its restricted state. This preliminary action prepares the system for upcoming configuration operations, ensuring that the port is accessible when needed. After configuration completes, the port is closed again. This preliminary opening and subsequent closing resolves the contradiction by proactively enabling access only when necessary, maintaining security during non-configuration periods.
Data Source
AI summary
An information processing system includes a first information processing device that includes a first processor, and one or a plurality of network ports whose opening is restricted during operation in a security mode in which security is ensured, wherein when settings to be compatible with the security mode are configured for a second information processing device that includes a second processor and one or a plurality of network ports, the first processor and the second processor are configured to: cause, in response to a predetermined trigger, the first information processing device and the second information processing device to shift from the security mode to a setting mode in which only the network port used in configuring the settings for the second information processing device is opened for operation; duplicate the settings in the first information processing device to the second information processing device via the opened network port after the first information processing device and the second information processing device shift to the setting mode; and cause, in response to completion of duplication of the settings, the first information processing device and the second information device to return to the security mode from the setting mode.


