Mediation Server Key Management for Secure Print Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network security methods, particularly for devices like printers, impose a heavy management load due to the need for constant private key management, which is challenging given their infrequent access and limited security mechanisms, leading to difficulties in establishing secure connections and managing multiple client devices.
Innovation Solution
A mediation apparatus that facilitates secure network communications by establishing preliminary connections, allowing remote status checking of service devices and mediating service demands, while centrally managing private keys to alleviate the load on client devices and simplify key management.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If private key management is implemented for security communication, then communication security is improved, but management load increases
Solution Approach 1:
The patent introduces a mediation apparatus as an intermediary between the service device and client devices. The mediation apparatus holds the private key and performs decryption, while the service device only needs to perform simple encryption. This mediator approach resolves the contradiction by centralizing complex key management in the mediation apparatus, relieving the service device of heavy management burden while maintaining security through the mediation apparatus's control over the private key.
Solution Approach 2:
The patent extracts the private key management function from the service device and relocates it to the mediation apparatus. The service device is relieved of storing and managing private keys, keeping only simple encryption capabilities. This extraction resolves the contradiction by removing the management burden from the service device while preserving security through the mediation apparatus's centralized key management.
2Speed
If one-to-one connection is established at arbitrary timing, then service responsiveness is improved, but network security control is worsened
Solution Approach 1:
The patent implements preliminary action by having the service device send encrypted notification data to the mediation apparatus before actual service requests. The mediation apparatus maintains a connection pool pre-established with client devices, allowing it to quickly forward requests without requiring new connection establishment. This resolves the contradiction by preparing communication channels in advance, enabling fast service response while maintaining security through the mediation apparatus's controlled connection management.
Solution Approach 2:
The mediation apparatus acts as an intermediary that manages connection timing and security. Client devices connect to the mediation apparatus rather than directly to service devices, allowing the mediation apparatus to control when connections are established and forwarded. This intermediary approach enables security-controlled connections while maintaining responsiveness through the mediation apparatus's ability to quickly forward authenticated requests.
3Reliability
If private key is stored in client devices, then communication security is improved, but ease of operation is worsened
Solution Approach 1:
The mediation apparatus serves as an intermediary that centralizes private key storage and management. Client devices and service devices both interact with the mediation apparatus, which handles all private key operations including decryption and re-encryption. This resolves the contradiction by eliminating the need for users to manually manage private keys in multiple devices, while maintaining security through the mediation apparatus's centralized cryptographic operations.
Solution Approach 2:
The mediation apparatus provides universal key management functionality for all client devices and service devices in the system. Instead of each device needing its own private key management capability, the mediation apparatus provides a unified key management service that all devices can use. This multi-functional approach improves ease of operation by providing a single point of key management while maintaining security through the mediation apparatus's cryptographic operations.
Data Source
AI summary
A mediation server 200 mediates a print demand from a client device 100 to a printing device 300. In order to elude a firewall F/W set between the mediation server 200 and the printing device 300, the printing device 300 first sends an HTTP request to the mediation server 200. The mediation server 200 sends back an HTTP response including a print demand to the printing device 300. Encrypted communication may be established between the client device 100 and the printing device 300 according to the following procedure. The mediation server 200 decrypts cipher data, which is encrypted with a public key by the client device, with a private key, re-encrypts the decrypted data with another private key, and mediates the encrypted data to the printing device 300. The printing device 300 decrypts the encrypted data with the public key and carries out printing. This arrangement enables the printing device to carry out printing in response to a demand from the client device via respective secure network environments.


