Authorization Server Token Segmentation for Cloud Print Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In cloud-based print services, the existing security mechanisms are inadequate to prevent unauthorized access and data leakage, particularly when using printer authorities to manage and update tokens, which can lead to malicious access and information exposure.
Innovation Solution
An authentication system that employs an authorization server to manage identification information for image forming devices, ensuring that only authorized devices can acquire print data from the print server through a mechanism that verifies the device's identity and authorization, thereby preventing unauthorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If the image forming device downloads print data using the token issued by the printer authority, then the image forming device can continue printing even if the expiration date is expired, but printer information or user information is not transmitted to the print server, allowing malicious third parties to download print data for other users
Solution Approach 1:
The patent introduces an authorization server as an intermediary between the image forming device and the print server. The authorization server issues tokens that contain both device identification information and user identification information, mediating the authentication process to ensure secure access while maintaining print continuation capability. This resolves the contradiction by providing a trusted third party that enables both functionality and security.
Solution Approach 2:
The patent segments the token into multiple components: device identification information, user identification information, and authorization scope. This segmentation allows the system to verify both the device's identity and the user's authority separately, preventing unauthorized access while maintaining legitimate print operations. The token structure is divided to include distinct fields for device ID, user ID, and expiration time.
2Reliability
If the common keys are leaked in the system that specifies an image forming device by using a first common key for creating a token and a second common key for identifying a device ID, then the device can be authenticated, but there remains a large security risk causing illegal access to all print data
Solution Approach 1:
The patent extracts the device identification information from the token and verifies it separately against registered device IDs stored in the authorization server. This separation allows the system to validate device identity without relying solely on secret keys, reducing the security risk associated with key leakage while maintaining authentication reliability.
Solution Approach 2:
The patent implements preliminary registration of device identification information in the authorization server before actual print operations. By pre-registering and storing device IDs, the system establishes a trusted baseline for authentication that reduces dependency on secret keys during operation, thereby mitigating security risks from potential key leakage.
3Reliability
If the server retains a device identifier by associating it with a user and verifies the device identifier upon login, then illegal access is prevented when user performs login, but illegal access is not prevented when the user does not perform login
Solution Approach 1:
The patent creates a universal authentication mechanism that works both for logged-in users and for devices operating autonomously. The token contains both device identification information and user identification information, enabling the same authentication protocol to serve dual purposes: verifying user-authenticated operations and validating device-initiated operations, thereby preventing illegal access in both scenarios.
Data Source
AI summary
An authentication system registers, in a service provision device, identification information for an information processing device that cooperates with the authentication system, associates the identification information for the information processing device with authorization information in accordance with an issuance of the authorization information corresponding to the information processing device, and saves them in the authorization service device, queries the authorization service device for the identification information for the information processing device associated with the authorization information in response to a request for obtaining the service and the issued authorization information from the information processing device, and provides, according to the request, the service with the information processing device in response to a correspondence between the identification information for the information processing device acquired as a result of the query and the identification information for the information processing device registered.


