Printer Driver Authorization List for Secure Printing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

There is a risk of confidential documents being leaked when users print from company PCs outside the internal office, as existing security measures are not effective in restricting printing to authorized printers, allowing users without administrator authority to create printer queues and print using unauthorized printers.

Innovation Solution

A printer driver that controls output based on a predetermined storage area containing information about authorized printing apparatuses, only allowing print data to be sent to registered printers and preventing output to unregistered printers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the administrator restricts the installation of printer driver by administrator authority, then the security of confidential documents is improved, but the ease of operation for users is worsened

Engineering Contradiction:
ImprovesecurityVSAvoidease of operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The printer driver stores in advance the list of authorized printing apparatuses and checks this list before allowing printing operations. This preliminary action of pre-storing authorized devices enables automatic authentication without requiring user intervention or administrator authority, thus maintaining security while improving ease of operation.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The printer driver performs self-authentication by automatically checking whether the target printing apparatus is in the pre-stored authorized list. This self-service mechanism eliminates the need for users to manually verify permissions or contact administrators, allowing secure printing operations to proceed automatically for authorized devices.

Inventive Principle:
Principle #25Self-service

2Adaptability or versatility

If the printer driver is preinstalled with support for multiple printing apparatuses, then the adaptability is improved, but the security is worsened due to potential unauthorized printing

Engineering Contradiction:
ImproveadaptabilityVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The printer driver applies different behaviors to different printing apparatuses based on their authorization status. Authorized apparatuses can receive print data while unauthorized apparatuses are blocked. This local differentiation of access rights maintains adaptability for supported devices while ensuring security by preventing unauthorized usage.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The printer driver pre-stores the list of authorized printing apparatuses before any printing operation occurs. This preliminary authentication setup enables the driver to adapt to multiple device types while maintaining security, as all potential printing targets are pre-evaluated against the authorized list before data transmission.

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If the user creates printer queue using USB Plug & Play function, then the ease of operation is improved, but the security is worsened due to potential connection to unauthorized printers

Engineering Contradiction:
Improveease of operationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The printer driver provides feedback by checking the authorization status of the printing apparatus before allowing printing operations. This feedback mechanism automatically blocks unauthorized devices while allowing authorized ones to function normally, thus maintaining ease of operation for legitimate use while preventing security breaches from unauthorized printers.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The printer driver performs preliminary authentication by checking whether the printing apparatus is in the pre-stored authorized list before allowing any printing operation. This preliminary check occurs automatically during the printing process, preventing unauthorized devices from receiving print data while maintaining seamless operation for authorized devices.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12197798B2Information processing apparatus registers printer driver for a selected image forming apparatus with administrator authority, control method of information processing apparatus, and non-transitory computer-readable storage medium
Publication Date: 2025.01.14 CANON KK
  • US12197798B2 patent drawing
  • US12197798B2 patent drawing
  • US12197798B2 patent drawing

AI summary

When a printer driver is installed, identification information of a printing apparatus set as an output destination of print data of the printer driver is registered in a print permission list in an administrator access area. The installed printer driver outputs the print data for the printing apparatus when the identification information of the printing apparatus to which the print data of the printer driver is output is registered in the print permission list. The installed printer driver does not output the print data for the printing apparatus when the identification information of the printing apparatus is not registered in the print permission list.