Cloud Device Endpoint Virtualization for Secure Job Routing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cloud computing systems lack secure and efficient methods for accessing and managing device endpoints, such as printers, across off-premise communications networks, leading to limitations in device availability and job routing when endpoints become unavailable.

Innovation Solution

The implementation of a cloud-based print service computing system that registers device endpoints as virtual objects, allowing secure access and job routing through virtual device identifiers and secure device endpoint identifiers, enabling seamless communication and job allocation across off-premise networks, even when physical devices are unavailable.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If device endpoints are accessed directly through off-premise networks, then network accessibility is improved, but security and reliability deteriorate due to lack of centralized management

Engineering Contradiction:
Improvenetwork accessibilityVSAvoiddevice availability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

A cloud-based device service acts as an intermediary between users and device endpoints. The service maintains a virtual device object that stores the secure device endpoint identifier, enabling indirect access through the cloud infrastructure. This mediator ensures centralized management while maintaining network accessibility, resolving the contradiction between ease of operation and reliability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If virtual device identifiers are mapped to secure device endpoint identifiers, then job routing flexibility is improved, but system complexity increases

Engineering Contradiction:
Improvejob routing flexibilityVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system segments identification into two distinct layers: virtual device identifiers for user-facing operations and secure device endpoint identifiers for actual device communication. The virtual device object stores the mapping between these layers, enabling flexible job routing without exposing the underlying complexity. This segmentation allows adaptability while managing system complexity through clear separation of concerns.

Inventive Principle:
Principle #1Segmentation

3Extent of automation

If device endpoints are registered with cloud service, then centralized management is improved, but data transmission overhead increases

Engineering Contradiction:
Improvecentralized managementVSAvoiddata transmission overhead
Core Design Contradiction:
Extent of automationVSLoss of energy

Solution Approach 1:

Device endpoints are registered with the cloud service in advance, and their secure device endpoint identifiers are stored in virtual device objects before actual job execution. This preliminary action establishes centralized management upfront, allowing subsequent job routing to proceed efficiently without repeated registration overhead. The mapping is prepared beforehand, reducing data transmission overhead during operational phases.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11868668B2Secure device endpoint assignment and job communication
Publication Date: 2024.01.09 MICROSOFT TECHNOLOGY LICENSING LLC
  • US11868668B2 patent drawing
  • US11868668B2 patent drawing
  • US11868668B2 patent drawing

AI summary

A device endpoint is accessed through an off-premise communications network relative to the device endpoint. The device endpoint is registered to a virtual device object in data storage of a device service, the device service and the device endpoint communicating across the off-premise communications network, the virtual device object storing a secure device endpoint identifier of the device endpoint. A virtual device identifier associated with the secure device endpoint identifier of the device endpoint is stored in the virtual device object. A request to access the device endpoint using the virtual device identifier is received. The secure device endpoint identifier associated with the virtual device identifier in the virtual device object is read. The device endpoint is notified of a pending job associated with the secure device endpoint identifier. The pending job is communicated to the device endpoint identified by the secure device endpoint identifier.