Terminal Device Mediator for Printer Security Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing information processing systems, such as those involving MFPs and servers, lack a mechanism to determine unauthorized access to MFPs via the Internet, posing a security risk when global IP addresses are exposed.

Innovation Solution

A communication system comprising a terminal device, a printer, and a confirmation server, where the terminal device sends a request signal with the printer's IP address to the confirmation server to determine if the printer is accessible via the Internet, and based on the response, executes a security process to prevent unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a mechanism for determining unauthorized access is provided in the MFP, then security determination capability is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity determination capabilityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a terminal device as an intermediary that performs the security determination function. Instead of embedding the determination mechanism directly in the MFP, the terminal device (such as a smartphone or PC) acts as a mediator that communicates with both the MFP and the server, executing the security check process externally while the MFP simply provides its IP address for checking.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Loss of energy

If security determination process is executed by the terminal device and server, then processing load on MFP is reduced, but system complexity increases

Engineering Contradiction:
Improveprocessing loadVSAvoidsystem complexity
Core Design Contradiction:
Loss of energyVSDevice complexity

Solution Approach 1:

The patent segments the security determination system into three distinct functional components: the MFP that provides its IP address, the terminal device that executes the determination logic and user interface, and the server that stores and manages IP address information. This segmentation distributes processing load away from the MFP while organizing system complexity into manageable, specialized modules.

Inventive Principle:
Principle #1Segmentation

3Adaptability or versatility

If the MFP uses a global IP address, then network accessibility is improved, but security risk increases

Engineering Contradiction:
Improvenetwork accessibilityVSAvoidsecurity risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements preliminary action by performing security determination before the MFP becomes vulnerable to unauthorized access. The system checks whether the MFP's global IP address is exposed to the Internet before potential attacks can occur, and can notify users or take preventive measures in advance, rather than reacting after an attack has happened.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10846030B2Communication device and non-transitory computer-readable medium storing computer-readable instructions for communication device or server
Publication Date: 2020.11.24 BROTHER KOGYO KK
  • US10846030B2 patent drawing
  • US10846030B2 patent drawing
  • US10846030B2 patent drawing

AI summary

A communication device may receive a target IP address from a target device; after the target IP address which is a global IP address has been received from the target device, send a request signal including the target IP address to a server, the request signal being for causing the server to send a specific signal, the specific signal including the target IP address as a destination IP address; determine whether first information is received from the server, wherein the first information is received from the server in a case where the server receives a response signal including the target IP address as a source IP address in response to the server having sent the specific signal; and in a case where it is determined that the first information is received, execute a security process.