Communication Apparatus Port Security Assessment via External Mediator

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional methods for determining if a multifunction peripheral (MFP) is publicly accessible on the global network do not adequately address security issues related to external apparatuses accessing the MFP over the Internet, as simply determining public accessibility is insufficient to ensure security.

Innovation Solution

A communication apparatus and method that involves receiving requests from external devices, transmitting responses, and performing an addressing process based on result information to address security issues concerning specific ports, using a processor and non-transitory computer-readable storage medium with program instructions to manage port information and security processes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If the MFP transmits request data specifying its own IP address as the destination IP address to determine public accessibility, then the determination process is simple, but the security assessment is insufficient

Engineering Contradiction:
Improvedetermination process simplicityVSAvoidsecurity assessment accuracy
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The security assessment is segmented into multiple independent tests: public accessibility determination, port reception capability testing, and security issue detection. Each test targets a specific aspect of security, allowing comprehensive assessment through separate, focused operations rather than a single complex determination

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

An external device is introduced as an intermediary to transmit test requests to the MFP and evaluate the responses. This intermediary performs the actual security testing by sending requests with specific destination IP addresses and port information, then analyzing whether the MFP receives and responds to these requests, providing an objective security assessment

Inventive Principle:
Principle #24Intermediary (Mediator)

2Loss of time

If the MFP only determines whether it is publicly accessible on the global network, then the detection process is quick, but security issues involving external apparatuses accessing the MFP cannot be adequately addressed

Engineering Contradiction:
Improvedetection timeVSAvoidsecurity vulnerability to external access
Core Design Contradiction:
Loss of timeVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary security testing by having the external device transmit test requests before actual external access occurs. The MFP's reception capability is pre-evaluated by checking whether it receives requests with its own IP address as destination, allowing security issues to be detected and addressed before they can be exploited by malicious external apparatuses

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The external device provides feedback by transmitting result information back to the MFP based on whether the MFP received the test requests. This feedback mechanism enables the MFP to understand its security status regarding external access, allowing operators to take corrective actions to address identified security vulnerabilities

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10922033B2Information processing apparatus transmitting requests and communication apparatus receiving the requests
Publication Date: 2021.02.16 BROTHER KOGYO KK
  • US10922033B2 patent drawing
  • US10922033B2 patent drawing
  • US10922033B2 patent drawing

AI summary

In a communication apparatus, a processor receives first and second requests from an external device via an internet. The first request has first port information indicating a first port. The second request has second port information indicating a second port. In response to receiving the first and second requests, the processor transmits first and second responses to the external device via the internet. After transmitting the first response and the second response, the processor receives result information from the external device via the internet. The result information is based on a fact that the external apparatus receives the first request and the second request; and performing an addressing process on a basis of the result information. The addressing process is for addressing a security issue concerning the first port and the second port.