Access Restricted File with Management Server Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems for access-restricted files struggle to securely manage access rights when important data is distributed externally, as they rely on cryptographic keys and do not allow for flexible changes in access restrictions or operation permissions, especially when printers at remote locations lack access to a management server.

Innovation Solution

The access restricted file includes confirming destination information for a management server to verify access rights, allowing operations only when the right is present, and periodically re-checks access rights to ensure secure data handling.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the concerned data was simply encrypted on that occasion, then the data security is improved, but it becomes impossible to monitor and maintain the security of the data concerned when a key of cryptograph has been obtained by using a certain illegal method and the encrypted data has been decrypted by using the above-obtained key of cryptograph

Engineering Contradiction:
Improvedata securityVSAvoidaccess restriction system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a management server as an intermediary between the encrypted data and the decryption process. The management server stores restriction information including cryptographic keys and monitors access requests, acting as a mediator that enables both security and controllability without requiring complex client-side implementation

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the security system into separate components: encrypted data storage, restriction information storage (including keys), and access monitoring functions. This segmentation allows the system to maintain security while enabling centralized control through the management server

Inventive Principle:
Principle #1Segmentation

2Reliability

If the printer that can print an image based on the encrypted data is limited to only such a printer that is provided with a function for accessing the management server, then the access control is improved, but it is impossible for the user to decrypt the encrypted data so as to print an image represented by the decrypted data, even though it is possible to change the restriction information registered in the management server

Engineering Contradiction:
Improveaccess controlVSAvoidprinter compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent enables printers to autonomously access the management server to obtain restriction information and cryptographic keys, performing self-service authentication and decryption operations without requiring manual intervention or complex configuration

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The management server provides universal access control services that can be utilized by any printer with network connectivity. The system design allows different types of printers to access the same restricted data through a common interface, enhancing versatility while maintaining security

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If the printer transmits the document ID of the encrypted document data concerned and the printer ID of its own, etc., to the management server so as to inquire an allowance or disallowance of the concerned printing operation, then the access monitoring is improved, but the operation time is increased due to network communication overhead

Engineering Contradiction:
Improveaccess monitoringVSAvoidoperation time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements preliminary authentication where the printer obtains cryptographic keys and restriction information from the management server before actual printing operations. This preliminary action reduces the need for repeated communication during the printing process, minimizing time loss

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system uses periodic access monitoring where the printer communicates with the management server at specific intervals or under specific conditions rather than continuously, reducing communication overhead while maintaining effective monitoring

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS8893305B2Access restricted file and access restricted file creating
Publication Date: 2014.11.18 KONICA MINOLTA BUSINESS TECH INC
  • US8893305B2 patent drawing
  • US8893305B2 patent drawing
  • US8893305B2 patent drawing

AI summary

Disclosed are an access restricted file and an restricted file creating apparatus for creating the access restricted file concerned, which makes it possible for an information processing apparatus to request a management server to determine whether the access right is present or absent. The apparatus includes a creating section to create the access restricted file that includes data, an accessing operation for which is restricted, and confirming destination information that represents the management server that confirms a presence or absence of the access right in regard to the operation for accessing the data. On the other hand, the access restricted file includes a program, being executable by a CPU of the information processing apparatus provided with a communicating function, to cause the CPU to perform a processing for requesting the management server, represented by the confirming destination information, to confirm the presence or absence of the access right.