MFP Scanner Policy Server Security via Mobile Device ID

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In shared office environments, existing security measures for Multi-Function Peripherals (MFPs) are costly and complex to implement, and difficult to manage, especially in settings where multiple users access the same device, leading to concerns about unauthorized document access and information leakage.

Innovation Solution

A scanner system with a management unit that registers account information on a shared policy server, accepts user identification from mobile devices, and controls encrypted file storage based on security policies, allowing only authorized operations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a shared office provider installs dedicated MFPs for each membership space, then document security is improved, but installation cost increases

Engineering Contradiction:
Improvedocument securityVSAvoidinstallation cost
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

A single MFP is made to serve multiple membership spaces by enabling it to read identification information from different mobile devices corresponding to different spaces. The MFP universally applies security policies based on the detected mobile device, allowing one device to secure multiple spaces without requiring dedicated MFPs for each space.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The mobile device acts as an intermediary carrier of identification information. Instead of requiring physical dedication of MFPs to each space, the mobile device mediates the connection between the user and the MFP, transmitting space-specific identification information that enables the MFP to apply appropriate security policies.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If policy servers and MFPs are set up for each membership space, then security control is improved, but setup time increases

Engineering Contradiction:
Improvesecurity controlVSAvoidsetup time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

A single policy server is made to serve multiple membership spaces by enabling it to recognize and process identification information from mobile devices corresponding to different spaces. The policy server universally manages security policies for multiple spaces through one centralized system rather than requiring separate policy servers for each space.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

Multiple security management functions for different membership spaces are merged into a single policy server. The policy server combines the management of multiple spaces' security policies into one unified system, eliminating the need to set up separate policy servers and reducing overall setup time.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If user identification systems are implemented in shared spaces, then document access security is improved, but operation complexity increases

Engineering Contradiction:
Improvedocument access securityVSAvoidoperation complexity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system enables self-service operation where the mobile device automatically provides identification information to the MFP without requiring manual user configuration or complex authentication procedures. The user simply presents their mobile device, and the system automatically retrieves and applies the appropriate security policy.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The manual or mechanical user identification and policy assignment process is replaced with an automated electronic system. The MFP automatically reads identification information from the mobile device and retrieves the corresponding security policy from the policy server, eliminating the need for manual user management and reducing operational complexity.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS11546488B2Scanner, scanner control method, and storage medium
Publication Date: 2023.01.03 CANON KK
  • US11546488B2 patent drawing
  • US11546488B2 patent drawing
  • US11546488B2 patent drawing

AI summary

In a Multi-Function Peripheral (MFP), identification information readable from an IC card is accepted, an administrator ID and an administrator password are used to access a policy server, a policy is registered in the policy server based on the accepted identification information, and storage of an encrypted file including image data obtained by a scan is controlled. A security setting in accordance with the policy based on the identification information is associated with the encrypted file, and a restriction of at least a part of an operation on the file is enabled in accordance with the security setting in accordance with the policy.