Cloud Print Access Control via Tenant Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In cloud print services, printing apparatuses face issues with unauthorized access and resource sharing, where administrators from one tenant may inadvertently allow users from other tenants to use the printing apparatus, leading to unintended usage and loss of control over print counting and printable sheet limits.
Innovation Solution
A printing apparatus with a registration unit and setting unit that allows administrators to determine which tenants can use the printer, processing print jobs only from authorized users, thereby implementing appropriate access control by checking the tenant name associated with each print job against the printer's permission settings.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a printing apparatus is registered in a cloud tenant and made accessible to users, then the printer becomes searchable and usable by users in the same tenant, but users from other tenants may gain unauthorized access and use the printer without proper control
Solution Approach 1:
The patent segments the cloud service into multiple isolated tenants, where each tenant has its own namespace and resource access controls. The printing apparatus is registered with a specific tenant ID, creating logical separation between different tenant groups. This segmentation ensures that users from one tenant cannot access printers registered to another tenant unless explicit sharing permissions are granted.
Solution Approach 2:
The patent implements preliminary action by pre-configuring tenant identification and access control settings during the printer registration process. The administrator sets up which tenants are permitted to access the printer before any users can attempt to use it. This preliminary configuration establishes security boundaries in advance, preventing unauthorized access attempts rather than relying on post-access control measures.
2Productivity
If a printer allows sharing across multiple tenants for resource utilization, then productivity improves, but control over print counting and printable sheet limits is lost
Solution Approach 1:
The patent introduces an intermediary layer in the form of a cloud-based print service that mediates between multiple tenants and the printing apparatus. This intermediary handles job routing, tenant verification, and usage tracking centrally. The printing apparatus itself remains simple, while the cloud service manages the complexity of multi-tenant coordination, print counting, and quota enforcement, thereby maintaining control without compromising sharing efficiency.
Solution Approach 2:
The patent applies local quality by allowing different access control policies and permission settings for different tenants accessing the same printer. Each tenant can have customized permissions, print quotas, and usage limits configured specifically for their group. This enables fine-grained control where each tenant experiences tailored access management while sharing the same physical resource.
3Adaptability or versatility
If the printing apparatus processes print jobs from any tenant, then service versatility is maximized, but security and authorization verification become complex
Solution Approach 1:
The patent extracts the complex authorization control logic from the printing apparatus itself and places it in the cloud-based print service. The printing apparatus only needs to perform simple operations: receive tenant identification from incoming print jobs and forward them to the cloud service for verification. The cloud service handles the complex tasks of tenant validation, permission checking, and access control policy enforcement, thereby reducing the complexity burden on the printing apparatus while maintaining versatile multi-tenant support.
Data Source
AI summary
Tenant information in which a printing apparatus is registered and tenant information of a user that is included in a print job are compared in the printing apparatus, and a user of another tenant is controlled not to freely use the printing apparatus, by providing an appropriate printing permission control method for a job of another tenant.


