Web-Enabled Printer Application Service Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Web-enabled printers lack a secure mechanism to prevent applications from accessing unauthorized network or device services during runtime, potentially leading to misbehavior or security breaches.

Innovation Solution

A system and method that allows developers to specify authorized services for their applications, which are stored in a database and monitored at runtime to prevent unauthorized access, ensuring that only approved services are accessed by the applications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If applications are allowed to access multiple network and device services freely, then application functionality and versatility are improved, but security and system stability deteriorate due to potential unauthorized access

Engineering Contradiction:
Improveapplication functionalityVSAvoidsystem security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent implements a preliminary action by requiring developers to declare the set of services their applications will access during the application submission and approval process. This declaration is stored in a database and used to create access control policies before the applications are deployed to the printer. By establishing these service access permissions in advance, the system ensures that applications can only access authorized services, preventing security breaches while maintaining necessary functionality.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If strict access control is implemented to prevent unauthorized service access, then system security is improved, but application versatility and ease of operation worsen due to restricted functionality

Engineering Contradiction:
Improvesystem securityVSAvoidapplication functionality
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent applies local quality by implementing fine-grained, application-specific access control policies. Instead of applying a uniform restriction to all applications, the system creates customized service access permissions for each application based on its declared requirements and the approval process. This allows each application to have the precise level of access it needs for its specific functionality, ensuring security without unnecessarily limiting versatility.

Inventive Principle:
Principle #3Local quality

3Ease of operation

If developer applications are allowed to run without monitoring, then ease of operation is improved, but harmful factors increase due to potential misbehavior and unauthorized access

Engineering Contradiction:
Improveapplication deploymentVSAvoidunauthorized service access
Core Design Contradiction:
Ease of operationVSObject-generated harmful factors

Solution Approach 1:

The patent implements feedback by creating a monitoring mechanism that tracks application behavior during runtime. The system monitors whether applications are attempting to access services outside their authorized set and provides feedback by blocking unauthorized access attempts. This continuous monitoring and feedback loop ensures that even if an application tries to misbehave or access unauthorized services, the system detects and prevents it, maintaining security while allowing legitimate operations to proceed smoothly.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10073967B2Controlling distribution and use of a developer application in a network environment
Publication Date: 2018.09.11 HEWLETT PACKARD DEVELOPMENT COMPANY LP
  • US10073967B2 patent drawing
  • US10073967B2 patent drawing
  • US10073967B2 patent drawing

AI summary

A method is disclosed for controlling distribution and use of a developer application in a network environment. A portal is provided for a developer to submit the developer application for use in the network environment. The developer application is operated for network devices that request use of the developer application. The developer application is operated to generate an output for individual network devices that request use of the developer application. The developer application is prevented from being operated on any of the individual network devices to access a service that is not part of a predetermined set of specified services that are allowed for that developer application.