Printer Print History Access Control via IPP Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current printer configurations that use Internet Printing Protocol (IPP) struggle to securely restrict access to print history information, allowing unauthorized users to obtain sensitive data by intercepting user identification information.

Innovation Solution

A printer system with a processor and memory that stores print history information, authentication data, and disclosure restriction information, which requests and verifies user input to determine if the user is authorized to receive restricted or non-restricted print history, ensuring only the intended user can access sensitive information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the printer stores user identification information in association with print history information to enable selective disclosure, then the print history information can be disclosed only to the print executing user, but the user identification information can be obtained by a third party who can then acquire the print history information by using the obtained user identification information

Engineering Contradiction:
Improvedisclosure control reliabilityVSAvoidunauthorized access to print history information
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the authentication verification process from the simple user identification matching approach. Instead of merely comparing user IDs, the system separately handles authentication information verification and user identity matching, removing the vulnerability where third parties could exploit obtained user IDs alone to access print history.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent implements preliminary authentication verification before disclosing print history information. The authentication process is performed in advance to confirm both the authenticity of authentication information and the identity of the requesting user, preventing unauthorized access before it can occur.

Inventive Principle:
Principle #10Preliminary action

2Object-affected harmful factors

If the printer implements authentication process requiring input information including user identification information and authentication information, then unauthorized access is prevented, but the operation complexity increases due to requiring users to input authentication information

Engineering Contradiction:
Improveunauthorized access preventionVSAvoiduser operation simplicity
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The patent makes the authentication mechanism universal by applying the same authentication process to both print execution and print history information access. This multi-functional approach allows the system to maintain security consistently across different operations while using the existing authentication infrastructure, reducing the need for separate complex authentication systems.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent implements feedback mechanisms where the printer provides clear responses about authentication status and disclosure permissions. The system feeds back whether authentication succeeded, whether the user is authorized to access the requested information, and what information can be disclosed, making the interaction transparent and easier to understand for users.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11194891B2Printer and non-transitory computer-readable recording medium storing computer-readable instructions for printer
Publication Date: 2021.12.07 BROTHER KOGYO KK
  • US11194891B2 patent drawing
  • US11194891B2 patent drawing
  • US11194891B2 patent drawing

AI summary

A printer may receive a history request according to IPP from a first external device, execute an authentication process. The printer may determine whether a specific user identified by first user identification information included in first input information is a disclosure-targeted user indicated by disclosure user information. The printer may, in a case where it is determined that first authentication information in a memory matches second authentication information and it is determined that the specific user is the disclosure-targeted user, send according to the IPP print history information including restricted history information and non-restricted history information to the first external device. The printer may, in a case where it is determined that the first authentication information matches the second authentication information and it is determined that the specific user is not the disclosure-targeted user, send according to the IPP the non-restricted history information to the first external device.