Virtual Network Connection Management for Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The security between multiple virtual networks is compromised when they are constantly connected, leading to potential vulnerabilities.

Innovation Solution

An information processing apparatus that forms and connects virtual networks only under specific conditions, such as user login or execution of a specific function, and then releases the connection after the function is completed, using a processor to manage virtual network connections and communications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If multiple virtual networks are always connected to each other, then network connectivity and functionality are improved, but security between the virtual networks deteriorates

Engineering Contradiction:
Improvenetwork connectivityVSAvoidsecurity vulnerability
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies dynamics by transitioning from static permanent connections to dynamic conditional connections. Virtual networks are connected only when specific conditions are met (such as user authentication, authorized function execution, or explicit policy approval) and disconnected when conditions cease to be valid. This dynamic connection model allows the network to adapt its topology based on real-time requirements while maintaining security through controlled access.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent implements local quality by applying different connection policies to different virtual network pairs based on their specific characteristics, trust levels, and functional requirements. Not all virtual networks are treated uniformly; instead, connection decisions are made individually for each network pair based on localized security assessments and functional needs, allowing selective connectivity that optimizes both security and functionality.

Inventive Principle:
Principle #3Local quality

2Adaptability or versatility

If virtual network connections are established frequently, then functional versatility is improved, but security management complexity increases

Engineering Contradiction:
Improvefunctional connectivityVSAvoidsecurity management
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent applies self-service by enabling virtual networks to autonomously manage their own connections based on pre-defined policies and conditions. Each virtual network entity can independently evaluate connection requests, authenticate against stored credentials, and establish or terminate connections without requiring centralized manual intervention. This self-service capability reduces security management complexity by distributing decision-making authority while maintaining consistent security standards through programmable policies.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent implements preliminary action by pre-establishing connection policies, authentication mechanisms, and security parameters before actual connection events occur. Security rules, trust relationships, and connection conditions are configured in advance, allowing rapid connection decisions when conditions are met without requiring real-time security analysis. This preliminary configuration reduces operational complexity by automating the decision-making process based on pre-agreed criteria.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12081366B2Information processing apparatus and non-transitory computer readable medium storing program
Publication Date: 2024.09.03 FUJIFILM BUSINESS INNOVATION CORP
  • US12081366B2 patent drawing
  • US12081366B2 patent drawing
  • US12081366B2 patent drawing

AI summary

An information processing apparatus includes a processor configured to form a first virtual network, connect the first virtual network to a second virtual network formed by another apparatus, in a case where a specific function is executed, and release a connection between the first virtual network and the second virtual network after the specific function is executed.