Shared-Space Image Forming VPN Access Without Local Org Data

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The challenge of connecting an information processing apparatus installed in a shared space, used by multiple users from different organizations, to a company's server via a virtual private network (VPN) without exposing confidential organizational information stored on the apparatus poses a security risk.

Innovation Solution

A system where the management server in the cloud holds company-specific information, and the information processing apparatus refers to this information to establish a VPN connection, ensuring that sensitive data is not stored locally, thus preventing information leakage.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If the information processing apparatus holds organization-specific information for establishing VPN connections, then the connection capability is improved, but the security is worsened due to potential information leakage in shared spaces

Engineering Contradiction:
ImproveVPN connection capabilityVSAvoidsecurity risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the organization-specific VPN connection information from the shared information processing apparatus and stores it externally in a secure location. The apparatus only holds a connection management program that can retrieve this information when needed, rather than permanently storing it locally. This extraction eliminates the security risk of holding confidential information in a shared environment while maintaining the ability to establish VPN connections.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a connection management program as an intermediary between the shared information processing apparatus and the organization-specific VPN information. This intermediary program acts as a secure bridge that temporarily accesses the external information storage, retrieves only the necessary connection details, and uses them to establish VPN connections without permanently storing the sensitive information in the shared apparatus.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Speed

If the information processing apparatus stores VPN connection information locally, then the connection speed is improved, but the information security is worsened due to exposure in shared environments

Engineering Contradiction:
Improveconnection establishment speedVSAvoidinformation security
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The patent performs preliminary actions by pre-configuring the connection management program with the capabilities and permissions needed to securely access external information storage. The program is prepared in advance to know how to retrieve VPN connection information safely, what authentication is required, and how to use the information temporarily without permanent storage. This preliminary setup enables fast connection establishment while maintaining security through pre-planned secure access procedures.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP4064024B1Information processing system, image forming apparatus, program, and information processing method
Publication Date: 2026.04.29 FUJIFILM BUSINESS INNOVATION CORP
  • EP4064024B1 patent drawingFigure 1
  • EP4064024B1 patent drawingFigure 2~3
  • EP4064024B1 patent drawingFigure 4

AI summary

An information processing system includes a first processor mounted on a first information processing apparatus installed in a shared space and shared by plural users who do not belong to the same organization, a second processor mounted on a connection server installed outside the shared space and connected to a local area network of an organization to which each of the plural users belong, and the connection server having a virtual private line connection function, and a third processor mounted on a management server which is installed outside the shared space and the local area network of each organization, and manages connection server connection information necessary for establishing a virtual private line with the connection server of each organization, in which the third processor is configured to, in response to a connection information acquisition request in which identification information on an organization transmitted from the first information processing apparatus is designated, return the connection server connection information corresponding to the organization designated in the connection information acquisition request, and the first processor is configured to connect a virtual private line with the connection server of the organization, by using the connection server connection information corresponding to the organization acquired by transmitting, to the management server, the connection information acquisition request including the identification information on the organization designated from a user of the first information processing apparatus.