Printing Apparatus Authentication Control via Communication Path Encryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing printing systems using the Internet Printing Protocol (IPP) face security issues due to the potential transmission of plaintext passwords over unencrypted communication paths, especially when hashing of passwords is not supported by certain print clients, leading to security vulnerabilities.

Innovation Solution

The printing apparatus dynamically varies the availability of the authentication printing function based on the encryption status of the communication path and the type of print client, ensuring that attribute information indicating support for authentication printing is only transmitted over encrypted paths and not supporting it over unencrypted paths, thereby preventing plaintext password transmission.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If authentication printing function is always transmitted as supported, then compatibility with all print clients is improved, but security is worsened due to plaintext password transmission risk over unencrypted paths

Engineering Contradiction:
Improvecompatibility with print clientsVSAvoidsecurity vulnerability
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The printing apparatus dynamically changes its attribute information response based on the encryption status of the communication path. When the path is encrypted, it transmits information indicating authentication printing is supported. When unencrypted, it transmits information indicating authentication printing is not supported. This dynamic adaptation resolves the contradiction by adjusting compatibility behavior according to security conditions.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The apparatus applies different quality characteristics to different communication contexts. For encrypted communication paths, it provides full authentication printing functionality. For unencrypted paths, it withholds this functionality. This local differentiation allows the system to maintain high security where needed while preserving compatibility where safe.

Inventive Principle:
Principle #3Local quality

2Ease of operation

If authentication printing is enabled over unencrypted paths, then ease of operation is improved, but security is worsened due to potential password interception

Engineering Contradiction:
Improveprinting accessibilityVSAvoidpassword interception risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The apparatus performs preliminary detection of the communication path's encryption status before enabling authentication printing. By detecting the unencrypted state in advance, it prevents the harmful action of password transmission over insecure paths. This preliminary anti-action blocks the security vulnerability before it can manifest.

Inventive Principle:
Principle #9Preliminary anti-action

Solution Approach 2:

The encryption status of the communication path acts as an intermediary condition that mediates between ease of operation and security. The apparatus uses this intermediary to determine whether to enable authentication printing, creating a conditional bridge between accessibility and security requirements.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If attribute information is transmitted over unencrypted paths, then communication efficiency is improved, but security is worsened due to information exposure

Engineering Contradiction:
Improvecommunication efficiencyVSAvoidinformation exposure
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The apparatus dynamically adjusts the content of attribute information transmitted over the communication path based on its encryption status. Over unencrypted paths, it withholds authentication printing capability information. Over encrypted paths, it provides complete information. This dynamic transmission strategy maintains efficiency while protecting sensitive information.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS10602016B2Printing apparatus, control method for printing apparatus, and storage medium
Publication Date: 2020.03.24 CANON KK
  • US10602016B2 patent drawing
  • US10602016B2 patent drawing
  • US10602016B2 patent drawing

AI summary

Ability information about an authentication printing function to be transmitted from a printing apparatus to a print client is varied depending on whether a communication path between the apparatuses is encrypted.