Shared-Space Image Processing for Secure Organization Job Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In shared workspaces where multiple users from different organizations use image processing apparatuses, the challenge is to execute jobs securely without storing confidential information related to each organization on the apparatus, which could lead to security breaches.
Innovation Solution
An image processing apparatus in a shared space executes jobs by connecting via a VPN to a management server hosting organization-specific information, allowing it to access necessary data without storing it locally, and using a mediating unit to facilitate communication with parent devices.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If the image processing apparatus stores organization-specific information and job data locally to execute jobs, then job execution capability is improved, but security is worsened due to risk of information leakage
Solution Approach 1:
The patent extracts organization-specific information (VPN credentials, authentication data) and job data from the image processing apparatus, storing them only in the management server. The apparatus retains only minimal identification information, thereby eliminating local storage of confidential data while maintaining job execution capability through remote data access.
Solution Approach 2:
The management server acts as an intermediary between the image processing apparatus and the organization's information systems. It stores organization-specific information and job data, and provides them to the apparatus as needed, enabling secure remote access without local storage of sensitive data.
2Reliability
If the image processing apparatus connects via VPN to access organization-specific information, then security is improved, but device complexity is worsened due to additional connection management
Solution Approach 1:
The management server provides multiple functions: storing organization-specific information, managing VPN connections, authenticating users, and facilitating job execution. By consolidating these functions in a single server, the patent avoids duplicating complex connection management logic in each image processing apparatus.
Solution Approach 2:
The image processing apparatus automatically establishes VPN connections and retrieves necessary information from the management server without requiring manual configuration or complex local security management, simplifying the user interface and operation.
3Adaptability or versatility
If multiple organizations share the same image processing apparatus, then resource utilization is improved, but security management is worsened due to multiple confidential information sets
Solution Approach 1:
The patent segments organization-specific information into separate storage units in the management server, with each organization's data isolated and accessed only through authenticated requests. This allows multiple organizations to share the same image processing apparatus while maintaining distinct security boundaries for each organization's confidential information.
Data Source
Figure 1
Figure 2~3
Figure 4A
AI summary
An image processing system includes: a first processor that is mounted on a first image processing apparatus, the first image processing apparatus being placed in a shared space, and configured to be used by plural users that do not belong to a same organization; a second processor that is mounted on a connection server, the connection server being placed outside the shared space, connected to a local area network of an organization to which at least one of the plural users belongs, and configured to connect a virtual private line; a third processor that is mounted on a second image processing apparatus, the second image processing apparatus being connected to the local area network of the organization; and a fourth processor that is mounted on a management server, the management server being placed outside the shared space and the local area network of the organization, and configured to manage connection server connection information used to establish the virtual private line with the connection server of the organization and access information used to access the second image processing apparatus of the organization, in which the third processor is configured to store, in the second image processing apparatus, a job relating to image processing generated by a user belonging to the organization, the fourth processor is configured to, in response to a connection information acquisition request in which organization identification information is designated being transmitted from the first image processing apparatus, return connection server connection information corresponding to an organization designated in the connection information acquisition request, and the first processor is configured to establish, via the virtual private line, connection with a connection server of an organization using the connection server connection information corresponding to the organization and acquired by transmitting, to the management server, the connection information acquisition request including the organization identification information designated by a user of the first image processing apparatus, acquire, in response to a job acquisition instruction including the organization identification information designated by the user of the first image processing apparatus, a job from the second image processing apparatus of the organization that is accessible using access information of the organization via the virtual private line, and execute the acquired job with the first image processing apparatus.