Encrypted Job Token Control for Secure Copy Quotas

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In sensitive environments, existing technologies lack effective control over the production and distribution of secure objects, such as documents and 3D articles, as users can exceed allocated print quotas and access rights, leading to unauthorized reproduction and distribution.

Innovation Solution

A method using a cloud-based quota/allocation service to enforce production control through a unique Job token, which is encrypted and linked to the object, allowing only authorized users and devices to decrypt and produce the object, with access rights and quotas managed by the content creator.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If users are allowed to access and produce secure objects, then productivity and ease of operation are improved, but unauthorized reproduction and distribution occur leading to loss of information and reduced reliability

Engineering Contradiction:
Improveproduction efficiencyVSAvoidunauthorized reproduction
Core Design Contradiction:
ProductivityVSLoss of information

Solution Approach 1:

The patent segments the secure object into two separate components: an encrypted main object and a job ticket containing decryption credentials. This segmentation allows the object to be accessed and produced efficiently while controlling distribution through the separable job ticket structure, preventing unauthorized reproduction of the complete secure object

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a policy enforcer as an intermediary component that mediates between the user and the secure object. The policy enforcer validates job tickets and controls decryption, enabling productive access while preventing unauthorized reproduction through centralized policy enforcement

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If production control and encryption are implemented, then reliability and security are improved, but device complexity and operational difficulty increase

Engineering Contradiction:
Improveaccess controlVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service mechanisms where the job ticket automatically contains all necessary decryption credentials and policy information. The production device can independently validate and process the job ticket without requiring complex external verification systems, maintaining high reliability while reducing system complexity

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent performs preliminary actions by pre-configuring the job ticket with decryption credentials and access policies before the production process. This preliminary preparation enables straightforward processing during production while ensuring reliable access control, reducing both operational complexity and processing time

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11480945B2Production device for production of an object for user permitted to print pre-defined number of copies of the object including encrypted token, and decrypted by the production device for determining user access right
Publication Date: 2022.10.25 HEWLETT PACKARD DEVELOPMENT COMPANY LP
  • US11480945B2 patent drawing
  • US11480945B2 patent drawing
  • US11480945B2 patent drawing

AI summary

A method tor regulating production of an object, the method comprising allocating access rights and a production quota to a user, the production quota to be fulfilled on an authorised production device using an encrypted unique job token embedded or comprised within or derived from the object and associated with the user and production device, receiving a user request to produce the object at the authorised production device, authenticating the user, decrypting the encrypted unique job token using a private key of the user and a private key of the production device, determining whether the production quota for the user related to the object has been met and on the basis of the determination, authorising the user request to produce the object at the authorised production device.