Cloud Print Access Control via Tenant Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In cloud print services, printing apparatuses face issues with unauthorized access and resource sharing, where administrators from one tenant may inadvertently allow users from other tenants to use the printing apparatus, leading to unintended usage and loss of control over print counting and printable sheet limits.

Innovation Solution

A printing apparatus with a registration unit and setting unit that allows administrators to determine which tenants can use the printer, processing print jobs only from authorized users, thereby implementing appropriate access control by checking the tenant name associated with each print job against the printer's permission settings.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a printing apparatus is registered in a cloud tenant and made accessible to users, then the printer becomes searchable and usable by users in the same tenant, but users from other tenants may gain unauthorized access and use the printer without proper control

Engineering Contradiction:
ImprovePrinter accessibility to usersVSAvoidUnauthorized access control
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments the cloud service into multiple isolated tenants, where each tenant has its own namespace and resource access controls. The printing apparatus is registered with a specific tenant ID, creating logical separation between different tenant groups. This segmentation ensures that users from one tenant cannot access printers registered to another tenant unless explicit sharing permissions are granted.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements preliminary action by pre-configuring tenant identification and access control settings during the printer registration process. The administrator sets up which tenants are permitted to access the printer before any users can attempt to use it. This preliminary configuration establishes security boundaries in advance, preventing unauthorized access attempts rather than relying on post-access control measures.

Inventive Principle:
Principle #10Preliminary action

2Productivity

If a printer allows sharing across multiple tenants for resource utilization, then productivity improves, but control over print counting and printable sheet limits is lost

Engineering Contradiction:
ImproveResource sharing efficiencyVSAvoidPrint control management
Core Design Contradiction:
ProductivityVSEase of operation

Solution Approach 1:

The patent introduces an intermediary layer in the form of a cloud-based print service that mediates between multiple tenants and the printing apparatus. This intermediary handles job routing, tenant verification, and usage tracking centrally. The printing apparatus itself remains simple, while the cloud service manages the complexity of multi-tenant coordination, print counting, and quota enforcement, thereby maintaining control without compromising sharing efficiency.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent applies local quality by allowing different access control policies and permission settings for different tenants accessing the same printer. Each tenant can have customized permissions, print quotas, and usage limits configured specifically for their group. This enables fine-grained control where each tenant experiences tailored access management while sharing the same physical resource.

Inventive Principle:
Principle #3Local quality

3Adaptability or versatility

If the printing apparatus processes print jobs from any tenant, then service versatility is maximized, but security and authorization verification become complex

Engineering Contradiction:
ImproveMulti-tenant service capabilityVSAvoidAuthorization control mechanism
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent extracts the complex authorization control logic from the printing apparatus itself and places it in the cloud-based print service. The printing apparatus only needs to perform simple operations: receive tenant identification from incoming print jobs and forward them to the cloud service for verification. The cloud service handles the complex tasks of tenant validation, permission checking, and access control policy enforcement, thereby reducing the complexity burden on the printing apparatus while maintaining versatile multi-tenant support.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS11188277B2Printing apparatus that supports a tenant of cloud computing
Publication Date: 2021.11.30 CANON KK
  • US11188277B2 patent drawing
  • US11188277B2 patent drawing
  • US11188277B2 patent drawing

AI summary

Tenant information in which a printing apparatus is registered and tenant information of a user that is included in a print job are compared in the printing apparatus, and a user of another tenant is controlled not to freely use the printing apparatus, by providing an appropriate printing permission control method for a job of another tenant.