Automated Cryptographic Signing for MFP Documents
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for cryptographic signing of documents generated by multifunction printers (MFPs) are cumbersome, insecure, and costly, as they require distributing and managing user digital certificates and private keys, which poses security risks and administrative burdens.
Innovation Solution
A secure scanning system that integrates with third-party applications, enabling automated cryptographic signing of MFP-generated documents without the need for additional devices or storage of user certificates on MFPs. This system uses biometrics and multi-factor authentication to authenticate users and maintains the private key off the network.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If user digital certificates are installed on each multifunction printer, then cryptographic signing capability is achieved, but maintenance cost and security risk increase
Solution Approach 1:
The patent extracts the private key from the multifunction printer environment entirely. Instead of installing certificates on MFPs, the system uses PKI cards that users carry personally, keeping the private key offline and isolated from the networked printer system. This eliminates the management burden while maintaining signing capability.
Solution Approach 2:
The patent introduces PKI cards as an intermediary device between the user and the multifunction printer. The card serves as a portable security token that authenticates users without requiring certificate installation on the printer itself, thus resolving the contradiction between capability and complexity.
2Reliability
If PKI cards are distributed to users, then cryptographic signing is enabled, but cost and management burden increase
Solution Approach 1:
The system enables users to self-authenticate using their PKI cards and biometric data without requiring administrator intervention for each signing operation. The automated authentication process reduces manual management overhead while maintaining security.
Solution Approach 2:
The patent replaces manual certificate management processes with automated biometric authentication. Fingerprint scanning and other biometric methods substitute for traditional password-based or card-based authentication, reducing administrative burden while enhancing security.
3Ease of operation
If private keys are transferred across the network, then signing operations can be performed remotely, but security risk increases
Solution Approach 1:
The patent extracts the private key from the network environment entirely by using offline PKI cards. The card remains physically with the user and never communicates the private key to the network, eliminating the security risk of network transmission while still enabling remote signing through secure authentication protocols.
Solution Approach 2:
The system prepares security measures in advance by authenticating users through biometric verification before any signing operation. This pre-authentication cushioning ensures that even if network communication occurs, the private key itself never leaves the secure offline environment of the PKI card.
Data Source
AI summary
A method, a non-transitory computer-readable medium, and a multifunction printer (MFP) that generate a signed digital document from a document generated by the multifunction printer. The method includes displaying a third-party screen for a third-party scan or fax workflow; switching to a multifunction printer vendor signing screen and obtaining signing settings for the generation of the signed digital document; calculating a document hash of the generated document using a cryptographic hashing algorithm; sending a digital signing request to a signing server, the digital signing request including the document hash of the generated document and an authenticated account identity of a user; receiving a digital signature and a public digital signing certificate for the user from the signing server; generating the signed digital document by embedding the digital signature and the public digital signing certificate of the user into the generated document; and switching to the third-party screen for the workflow.


