Network Port Security Verification for Multifunction Peripherals
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
There is a risk of accidentally lowering the security level of a network with high security by mistakenly leaking connection information to a network with a lower security level, particularly in scenarios where multifunction peripherals are connected to both secure and general local area networks.
Innovation Solution
An information processing apparatus with two ports, one connected to a high-security network and the other to a low-security network, uses stored setting information to determine proper network connections, preventing accidental data transmission to the wrong network by employing a determining unit that checks for proper network connections based on security levels and IP addresses.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If setting information for high-security network is accidentally leaked to low-security network, then network connection versatility is improved, but security level deteriorates
Solution Approach 1:
The determining unit performs preliminary verification by attempting to connect to the first network using second setting information (intended for the second network) before allowing actual communication. This preliminary action detects potential misconfiguration or leakage scenarios before they can compromise security.
Solution Approach 2:
The system implements feedback control by continuously monitoring network connection results and using this information to determine whether to permit or prohibit communication. The determining unit receives feedback from connection attempts and adjusts communication permissions accordingly, preventing security breaches while allowing legitimate connections.
2Reliability
If network connection verification is performed, then security level is improved, but device complexity increases
Solution Approach 1:
The information processing apparatus performs self-verification by automatically attempting to connect to networks using stored setting information and determining whether connections are appropriate. The system serves itself by autonomously detecting misconfigurations and adjusting communication permissions without external intervention, reducing the need for complex external verification systems.
Solution Approach 2:
The determining unit changes operational parameters dynamically based on connection results. When connection verification succeeds or fails, the system adjusts communication permissions (permit or prohibit) accordingly. This parameter-based control simplifies the overall system architecture compared to rule-based or configuration-based approaches.
Data Source
AI summary
An information processing apparatus includes a first port, a second port, a storage device, and a determining unit. The first port is to be connected to a first network having a first security level. The second port is to be connected to a second network having a second security level. The second security level is lower than the first security level. The storage device holds first setting information for connection to the first network and second setting information for connection to the second network. The determining unit makes network connection to at least the first port in accordance with the second setting information and determines, on the basis of a result from the network connection to at least the first port in accordance with the second setting information, whether the network connection to the first port is made properly.


