Ephemeral Key Pair Trust for Cloud Content Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Openly accessible content creation devices, such as multifunction printers, pose a security risk as they may not ensure secure connections to cloud services, potentially caching or mishandling sensitive data, and users lack control over the encryption and authentication processes.

Innovation Solution

Establishing a three-way trust relationship between a content creation device, a mobile device, and a cloud service using certified applications that generate ephemeral key pairs for secure data transfer and storage, ensuring that data is encrypted and protected from unauthorized access, even when stored on the cloud service.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If openly accessible content creation devices are used for cloud service connections, then device accessibility and ease of operation are improved, but security and data protection are worsened

Engineering Contradiction:
Improvedevice accessibilityVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces certified applications as intermediary components that mediate between the content creation device and cloud service. These certified applications establish trust relationships and handle authentication, acting as a security intermediary that allows open device access while maintaining controlled security protocols. The certified application on the content creation device communicates with a mobile certified application, which then interacts with the cloud service, creating a layered intermediary structure.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The security system is segmented into multiple independent components: a certified application on the content creation device, a mobile certified application on the mobile device, and the cloud service. Each segment has specific security responsibilities - the certified application manages local trust relationships, the mobile certified application handles authentication and key management, and the cloud service provides secure data storage. This segmentation allows each component to be optimized for its specific security function while maintaining overall system accessibility.

Inventive Principle:
Principle #1Segmentation

2Reliability

If certified applications with ephemeral key pairs are implemented, then data protection and security are improved, but device complexity and system configuration are worsened

Engineering Contradiction:
Improvedata protectionVSAvoidsystem configuration
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The certified applications automatically generate ephemeral key pairs and establish trust relationships without requiring manual user configuration. The mobile certified application autonomously manages authentication credentials, generates session keys, and coordinates security handshakes with the content creation device and cloud service. This self-service capability reduces the perceived complexity for users while maintaining robust cryptographic protection.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

Trust relationships and authentication mechanisms are established in advance before actual data transfer occurs. The certified application pre-configures security parameters, generates necessary cryptographic keys, and validates trust relationships beforehand. This preliminary security setup ensures that when data transfer is needed, the complex authentication processes have already been completed, reducing operational complexity during actual use.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If three-way trust relationships are established between devices and cloud service, then authentication security is improved, but connection establishment time and process complexity are worsened

Engineering Contradiction:
Improveauthentication securityVSAvoidconnection establishment time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary authentication and trust verification actions before actual data transfer to prevent security issues during operation. The mobile certified application pre-establishes trust relationships with both the content creation device and cloud service, conducting security validations in advance. This preliminary anti-action approach ensures that when real data transfer occurs, the authentication framework is already in place, reducing the time penalty of security checks during critical operations.

Inventive Principle:
Principle #9Preliminary anti-action

Data Source

PatentUS11588809B2System and method for securing a content creation device connected to a cloud service
Publication Date: 2023.02.21 GENESEE VALLEY INNOVATIONS LLC
  • US11588809B2 patent drawing
  • US11588809B2 patent drawing
  • US11588809B2 patent drawing

AI summary

A certified application is installed onto a content creation device and a mobile certified application is installed onto a mobile device, the applications establish first and second trust relationships with the cloud service. The certified application and mobile certified application establish the third trust relationship via a proximity network. The mobile certified application generates a first ephemeral key pair having a private part. The certified application generates a second ephemeral key pair having a private part. The mobile certified application requests a service from the content creation device involving the transfer of data between the content creation device and the cloud service. The data is protected by at least one of the first and second ephemeral key pairs in response to invocation of the service. The service results in the data being stored at the cloud service and/or rendered at the content creation device.