Relay Server Allowance List for Secure Software Updates

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems managing connection destinations on the Internet using white lists lack efficient mechanisms for secure software updates and downloads, particularly for devices like image forming apparatuses, which require reliable and secure communication protocols to prevent unauthorized access and ensure data integrity.

Innovation Solution

An information processing apparatus with a memory for storing an allowance list of permitted server locations, a receiving unit for software update inquiries, and a transmitting unit for secure communication with management servers, storage servers, and client apparatuses, ensuring that only authorized connections are established through a relay server for secure software downloads and updates.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a white list is used to manage connection destinations, then network security is improved, but the complexity of managing software updates and downloads increases

Engineering Contradiction:
Improvenetwork securityVSAvoidsoftware update management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The relay server acts as an intermediary between the client apparatus and the storage server. It receives software download requests from clients, checks them against the allowance list, and only forwards authorized requests to the storage server. This mediator approach maintains security through the white list while simplifying client-side software update management.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary action by pre-establishing the allowance list with authorized storage server locations before software downloads occur. The relay server checks the allowance list in advance of each download request, preventing unauthorized connections before they can occur.

Inventive Principle:
Principle #10Preliminary action

2Object-affected harmful factors

If an allowance list is maintained for authorized connections, then unauthorized access is prevented, but the process of adding new authorized servers becomes more complex

Engineering Contradiction:
Improveunauthorized accessVSAvoidease of adding authorized servers
Core Design Contradiction:
Object-affected harmful factorsVSEase of manufacture

Solution Approach 1:

The management server provides feedback by automatically updating the allowance list with new authorized storage server locations. When a new server is added to the system, the management server receives information about it and updates the allowance list accordingly, eliminating the need for manual configuration changes at the relay server.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The relay server performs self-service by automatically receiving updated allowance list information from the management server and applying it without manual intervention. The system self-updates its security list, making it easy to add new authorized servers while maintaining strong access control.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS8661127B2Information processing apparatus, information processing method, non-transitory computer readable medium storing program, and information processing system
Publication Date: 2014.02.25 FUJIFILM BUSINESS INNOVATION CORP
  • US8661127B2 patent drawing
  • US8661127B2 patent drawing
  • US8661127B2 patent drawing

AI summary

An information processing apparatus includes a memory storing an allowance list, a first receiving unit that receives a first request from a client apparatus, a first transmitting unit that transmits the first request to a management server, a second receiving unit that receives a first response which include first location information indicating a position of a storage server storing software from the management server, an adding unit that adds the first location information to the allowance list, a second transmitting unit that transmits the first response to the client apparatus, a third receiving unit that receives a second request including second location information from the client apparatus, a third transmitting unit that transmits the second request to the storage server, a fourth receiving unit that receives a second response from the storage server, and a fourth transmitting unit that transmits the second response to the client apparatus.