MFP Medium Access Control via User Login State Binding
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing image forming apparatuses, such as MFPs, face challenges in preventing unauthorized access to media inserted into the device, leading to potential data leakage and complicating user operations, as existing solutions either fail to prevent data leakage or unnecessarily restrict media usage.
Innovation Solution
An image forming apparatus that includes a read unit to read unique information from the media, storage units to store and correlate user and media information, and a control unit to manage access permissions based on user authentication and media status, ensuring only authorized users can access the media without complex operations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If existing solutions prohibit medium use after a reference time or invalidation period, then data leakage is prevented, but usability is deteriorated and complicated operations are required
Solution Approach 1:
The system automatically manages medium authorization by detecting user login states and medium insertion/removal events. The authorization management unit automatically authorizes or invalidates medium access based on detected states, eliminating the need for manual user operations while ensuring data security.
Solution Approach 2:
The system continuously monitors user login status and medium insertion/removal events, providing real-time feedback to the authorization management unit. This feedback mechanism enables dynamic adjustment of medium access permissions, maintaining security while improving usability through automatic adaptation to current system state.
2Ease of operation
If existing solutions detect user absence and display warnings, then forgotten medium removal is prevented, but data leakage cannot be stopped and device complexity increases
Solution Approach 1:
The system performs preliminary authorization by binding medium access permissions to user login status before data access occurs. When a user logs in, the authorization management unit proactively authorizes medium access; when logged out, access is automatically invalidated, preventing data leakage before it can occur.
Solution Approach 2:
The authorization management unit acts as an intermediary between the user authentication system and the medium access control. It receives authentication state information and translates it into appropriate medium access permissions, separating the security logic from the user interface and simplifying the overall system architecture.
3Reliability
If authorized users must perform authorization operations again after medium use is prohibited, then security is maintained, but operation complexity increases
Solution Approach 1:
The system automatically manages authorization states based on user login detection. When a user logs in with a registered medium inserted, the authorization management unit automatically restores access permissions without requiring manual authorization operations, eliminating operational complexity while maintaining security through state-based control.
Data Source
AI summary
When a user logs in to an MFP and inserts a medium, a serial number of the medium is stored in a device information database in correspondence with user information of the user, and a descramble key, e.g., a hash code of the serial number is registered in the user information. When the medium is removed from the MFP which is still logged in, the registration is deleted. When the MFP into which the medium is still inserted is logged out, no registration is deleted. When the user logs in to the MFP into which the medium is already inserted, the MFP determines whether a descramble key is registered in user information of the user. When a second user logs in to an MFP from which a first user had logged out while forgetting to remove a medium, the MFP prohibits the second user from accessing the medium because no descramble key is registered in user information of the second user.


