Security Setting Determination During Software Updates
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing information processing systems face challenges in setting appropriate security settings during software updates, as they often rely on default values that may compromise security or ignore changes, leading to potential vulnerabilities and usability issues.
Innovation Solution
An information processing apparatus with a storage unit, update unit, and determination unit that determines setting values for newly added or changed security setting items based on stored values, ensuring appropriate security settings are maintained during software updates.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If default setting values are used for newly added security setting items during software updates, then usability is improved and configuration is simplified, but security is compromised because default values may disable security functions or not contribute to security improvement
Solution Approach 1:
The system performs preliminary analysis of the relationship between newly added security setting items and existing setting items before software update. It identifies candidate setting values by examining historical setting values and usage patterns, preparing security-conscious default values in advance rather than using generic defaults.
Solution Approach 2:
The system incorporates feedback from historical setting values and usage patterns to determine appropriate setting values for newly added security items. By analyzing how similar settings were configured in previous versions and their actual usage, the system can infer secure default values that align with user intentions and security best practices.
2Stability of the object's composition
If setting values are inherited without change during software updates, then configuration consistency is maintained, but compromised security functions are inherited and used, creating vulnerability
Solution Approach 1:
The system performs preliminary analysis before software update to identify security-related setting items that may be affected by the update. It proactively determines whether inherited setting values are appropriate or need adjustment, rather than passively inheriting all values without review.
Solution Approach 2:
The system dynamically adjusts setting values based on the software update content and security requirements. When a security vulnerability is detected in inherited settings or when the update introduces new security considerations, the system modifies the parameter values to maintain security while preserving configuration consistency where appropriate.
3Device complexity
If only the difference between setting values before and after update is presented, then information presentation is simplified, but user understanding of security settings is difficult and appropriate setting determination is challenging
Solution Approach 1:
The system introduces an intermediary explanation layer that connects the simple difference presentation with comprehensive security information. It provides rationale explanations, security impact assessments, and usage context as intermediate information that helps users understand why certain setting changes are recommended, bridging the gap between simplicity and comprehensiveness.
4Adaptability or versatility
If security setting items are added or specifications changed during software update, then functionality is improved, but determining appropriate setting values becomes more complex and time-consuming
Solution Approach 1:
The system performs preliminary analysis of the software update content and identifies all affected security setting items before the update is applied. It pre-calculates candidate setting values and prepares recommendation information in advance, reducing the time required for setting determination during and after the update process.
Solution Approach 2:
The system automatically determines candidate setting values for newly added or changed security items by analyzing the update content, historical data, and security requirements. This self-service capability reduces the manual effort and time required for setting determination, allowing the system to handle the complexity autonomously while providing recommendations to the user.
Data Source
AI summary
An information processing apparatus includes a storage unit configured to store a setting value for each of a plurality of security setting items, an update unit configured to perform update processing on software stored in the information processing apparatus, and a determination unit configured to determine a setting value of a setting item that is newly added or changed in a specification of the software through the update processing, based on the setting values stored in the storage unit.


