Security Policy Distribution for Image Processing Apparatus

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Administering settings compliant with a security policy to image processing apparatuses is time-consuming and labor-intensive due to the need to check and update applications, especially when existing applications cannot be made compliant through OS settings alone.

Innovation Solution

An information processing apparatus and method that includes a setting determination unit to assess if an application can be set to security policy settings, an update unit to update the application if necessary, and a distribution unit to distribute the settings, ensuring compliance without impairing the application's functionality.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the administrator manually checks and updates applications to make them compliant with security policy settings, then security policy compliance is achieved, but the time and effort required increases significantly

Engineering Contradiction:
Improvesecurity policy complianceVSAvoidadministrator time and effort
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The image processing apparatus automatically determines compatibility between its applications and security policy settings without requiring administrator intervention. The determination unit autonomously checks whether applications can operate with the distributed security settings, and the system self-manages the compatibility assessment process, eliminating the need for manual administrator checking and updating of applications.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary compatibility determination before distributing security policy settings. By having the determination unit assess application compatibility in advance, the system prepares the necessary information about which applications can and cannot comply with the security policy, allowing for smoother and faster distribution without time-consuming manual checks during the actual security policy implementation.

Inventive Principle:
Principle #10Preliminary action

2Measurement precision

If the administrator checks each application individually for compatibility with security settings, then accurate compliance determination is achieved, but the process becomes increasingly time-consuming as the number of image processing apparatuses increases

Engineering Contradiction:
Improvecompliance determination accuracyVSAvoiddistribution efficiency
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

Each image processing apparatus's determination unit independently and autonomously determines the compatibility of its own applications with the security policy settings. This self-service approach ensures accurate compliance determination for each device without requiring centralized manual checking, thereby maintaining precision while scaling efficiently across multiple apparatuses.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The compatibility determination process is segmented and distributed to individual image processing apparatuses rather than being centralized. Each apparatus independently performs the determination for its own applications, dividing the overall compliance checking task into independent units that can operate simultaneously, thus maintaining accuracy while improving overall distribution efficiency across the network.

Inventive Principle:
Principle #1Segmentation

3Speed

If security policy settings are distributed without checking application compatibility, then distribution speed increases, but application functionality may be impaired

Engineering Contradiction:
Improvesettings distribution speedVSAvoidapplication functionality
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The determination unit performs compatibility checking in advance before the actual distribution of security policy settings. This preliminary assessment identifies which applications can and cannot comply with the intended security settings, allowing the distribution process to proceed at full speed while ensuring that incompatible applications are identified and handled appropriately to maintain their functionality.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system provides feedback information about application compatibility to the distribution process. The determination unit communicates compatibility results back to the distribution mechanism, enabling intelligent distribution decisions that maintain application functionality while achieving fast distribution speeds through automated compatibility management rather than slow manual verification.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10027713B2Information processing apparatus that distributes settings compliant with security policy and control method therefor, image processing apparatus and control method therefor, information processing system and control method therefor, and storage medium
Publication Date: 2018.07.17 CANON KK
  • US10027713B2 patent drawing
  • US10027713B2 patent drawing
  • US10027713B2 patent drawing

AI summary

An information processing apparatus that makes it possible to save time and effort expended by an administrator on distribution of settings compliant with a security policy. Whether or not an application installed in the image processing apparatus to which setting values compliant with a security policy are to be distributed can be set to the settings is determined. When it is determined that the application cannot be set to the settings, whether or not the application can be set to the settings by updating thereof is determined. When the determination result indicates that the settings can be set by updating the application, the application is updated, and the settings are distributed to the image processing apparatus.