Information Processing Apparatus Security Policy Conflict Prevention

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing information processing apparatuses lack a solution to manage conflicts between security policy settings and collective settings for security-related functions, particularly when these functions overlap.

Innovation Solution

An information processing apparatus is designed with a first function to set a security policy and a second function to collectively set recommended security values, including control to prevent conflicting settings when a security policy is already set.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If both security policy function and collective setting function are provided, then security configuration flexibility is improved, but setting conflict occurs

Engineering Contradiction:
Improvesecurity configuration flexibilityVSAvoidsetting consistency
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system performs preliminary detection of whether a security policy is currently set before allowing collective setting operations. This preliminary action prevents conflicts by blocking collective setting when a security policy exists, ensuring consistent security configurations without requiring complex conflict resolution logic during execution.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The control unit acts as an intermediary that mediates between the security policy function and collective setting function. It detects the presence of security policies and controls the collective setting operation accordingly, preventing conflicts without requiring the two functions to directly interact or resolve conflicts between themselves.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If security policy setting is allowed to be overwritten, then collective setting flexibility is improved, but security policy integrity deteriorates

Engineering Contradiction:
Improvecollective setting flexibilityVSAvoidsecurity policy integrity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system applies preliminary anti-action by detecting the presence of a security policy before allowing collective setting operations. When a security policy is detected, the system prevents the collective setting from overwriting the policy settings, thereby protecting security policy integrity before any potential conflict can occur.

Inventive Principle:
Principle #9Preliminary anti-action

Solution Approach 2:

The system extracts the security policy settings from the general setting hierarchy by detecting their presence and isolating them from collective setting operations. This extraction ensures that security policy settings remain separate and unaffected by collective setting changes, maintaining their integrity while still allowing collective setting for other non-conflicting parameters.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS20250094610A1Information processing apparatus, control method for information processing apparatus, and storage medium
Publication Date: 2025.03.20 CANON KK
  • US20250094610A1 patent drawing
  • US20250094610A1 patent drawing
  • US20250094610A1 patent drawing

AI summary

An information processing apparatus having a first function and a second function which is a function different from the first function, in the first function, sets, to the information processing apparatus, a first setting value group associated with a security policy set to the information processing apparatus, in the second function, sets, to the information processing apparatus, a second setting value group associated with one usage environment selected from among a plurality of usage environments, and in a case where the security policy is currently set to the information processing apparatus in the first function, in the second function, performs control to prevent a setting value group associated with any usage environment in the plurality of usage environments from being set to the information processing apparatus, wherein the first setting value group and the second setting value group include setting values corresponding to an identical setting item.