Cloud Print Sandbox for Secure Data Transmission

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current image forming devices lack efficient methods for supporting cloud print services, particularly in managing and transmitting print data across different areas within a device while ensuring user authentication and security.

Innovation Solution

A device and method for cloud print service support, including a control unit for acquiring and transmitting print data, a user interface for user authentication, and a communication unit for secure data transmission to a cloud print server, utilizing a UNIX series operating system and the Common UNIX Printing System (CUPS) with security reinforcement techniques like sandboxing.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If print data is acquired in a user area from system area, then cloud print service functionality is enabled, but security risks increase due to cross-area data access

Engineering Contradiction:
Improvecloud print service functionalityVSAvoidsecurity risks
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a sandbox as an intermediary mechanism between the system area and user area. The sandbox provides a controlled environment where print data can be accessed and processed, mediating the interaction between different areas while maintaining security boundaries. This allows cloud print service functionality to operate without direct cross-area data access, thereby reducing security risks.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the device memory into distinct areas: system area, user area, and sandbox area. This segmentation isolates different functional components and data types, allowing secure interaction between areas through controlled interfaces. The sandbox acts as a segmented zone that processes print data without exposing the broader system structure, enabling cloud print services while maintaining security through architectural separation.

Inventive Principle:
Principle #1Segmentation

2Reliability

If user authentication is implemented, then security is improved, but device complexity increases due to additional authentication mechanisms

Engineering Contradiction:
Improveuser authentication securityVSAvoidauthentication mechanism complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service authentication where the sandbox automatically handles authentication processes without requiring complex manual intervention. The authentication mechanism is integrated into the sandbox's operational framework, allowing it to autonomously verify user credentials and manage access rights. This reduces the visible complexity of authentication mechanisms while maintaining strong security through automated, embedded authentication logic.

Inventive Principle:
Principle #25Self-service

3Adaptability or versatility

If data transmission to cloud server is enabled, then cloud print service capability is improved, but security vulnerabilities increase due to network data transmission

Engineering Contradiction:
Improvecloud print service capabilityVSAvoidsecurity vulnerabilities
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The sandbox serves as an intermediary that prepares and validates print data before transmission to the cloud server. It acts as a security buffer, ensuring that only authorized and properly formatted data is transmitted over the network. This intermediary layer prevents direct exposure of system resources to network vulnerabilities while enabling cloud print service capability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements preliminary security checks and data validation within the sandbox before data is transmitted to the cloud server. Authentication and authorization decisions are made in advance within the sandbox environment, ensuring that security protocols are established before network transmission occurs. This preliminary action prevents security vulnerabilities from affecting the data transmission process.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10298809B2Device for supporting cloud print service and method of providing cloud print service
Publication Date: 2019.05.21 HEWLETT PACKARD DEVELOPMENT COMPANY LP
  • US10298809B2 patent drawing
  • US10298809B2 patent drawing
  • US10298809B2 patent drawing

AI summary

A device for supporting a cloud print service includes a control unit configured to control so that print data generated in a first area is acquired in a second area, a user interface unit configured to provide a user interface for performing user authentication according to the acquisition of the print data and receive authentication information from a user through the user interface, and a communication unit configured to transmit the acquired print data to a cloud print server if the user authentication succeeds by using the received authentication information.