Shared-Space Image Forming VPN Access Without Local Org Data
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The challenge of connecting an information processing apparatus installed in a shared space, used by multiple users from different organizations, to a company's server via a virtual private network (VPN) without exposing confidential organizational information stored on the apparatus poses a security risk.
Innovation Solution
A system where the management server in the cloud holds company-specific information, and the information processing apparatus refers to this information to establish a VPN connection, ensuring that sensitive data is not stored locally, thus preventing information leakage.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If the information processing apparatus holds organization-specific information for establishing VPN connections, then the connection capability is improved, but the security is worsened due to potential information leakage in shared spaces
Solution Approach 1:
The patent extracts the organization-specific VPN connection information from the shared information processing apparatus and stores it externally in a secure location. The apparatus only holds a connection management program that can retrieve this information when needed, rather than permanently storing it locally. This extraction eliminates the security risk of holding confidential information in a shared environment while maintaining the ability to establish VPN connections.
Solution Approach 2:
The patent introduces a connection management program as an intermediary between the shared information processing apparatus and the organization-specific VPN information. This intermediary program acts as a secure bridge that temporarily accesses the external information storage, retrieves only the necessary connection details, and uses them to establish VPN connections without permanently storing the sensitive information in the shared apparatus.
2Speed
If the information processing apparatus stores VPN connection information locally, then the connection speed is improved, but the information security is worsened due to exposure in shared environments
Solution Approach 1:
The patent performs preliminary actions by pre-configuring the connection management program with the capabilities and permissions needed to securely access external information storage. The program is prepared in advance to know how to retrieve VPN connection information safely, what authentication is required, and how to use the information temporarily without permanent storage. This preliminary setup enables fast connection establishment while maintaining security through pre-planned secure access procedures.
Data Source
Figure 1
Figure 2~3
Figure 4
AI summary
An information processing system includes a first processor mounted on a first information processing apparatus installed in a shared space and shared by plural users who do not belong to the same organization, a second processor mounted on a connection server installed outside the shared space and connected to a local area network of an organization to which each of the plural users belong, and the connection server having a virtual private line connection function, and a third processor mounted on a management server which is installed outside the shared space and the local area network of each organization, and manages connection server connection information necessary for establishing a virtual private line with the connection server of each organization, in which the third processor is configured to, in response to a connection information acquisition request in which identification information on an organization transmitted from the first information processing apparatus is designated, return the connection server connection information corresponding to the organization designated in the connection information acquisition request, and the first processor is configured to connect a virtual private line with the connection server of the organization, by using the connection server connection information corresponding to the organization acquired by transmitting, to the management server, the connection information acquisition request including the identification information on the organization designated from a user of the first information processing apparatus.