Pseudo Identity for Secure Shared Appliance Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Secure printing techniques face challenges with printer jams and toner outages, where print jobs are often stuck, and exposure of credentials is a concern, especially in untrusted environments, necessitating a method for secure access to shared appliances.

Innovation Solution

A system with three trust regions: a server and database for user and appliance registration, pseudo identities for appliances, and user-delegated permissions, allowing secure resource retrieval at shared appliances by using identifiers and credentials for authentication and access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If secure printing techniques are implemented to protect sensitive documents, then document security is improved, but handling of printer jams and toner outages becomes difficult

Engineering Contradiction:
Improvedocument securityVSAvoidprinter maintenance accessibility
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system separates authentication credentials from the printing function by introducing a pseudo identity that acts as an intermediary. The real user identity is segmented from the appliance interaction, allowing the appliance to be accessed without exposing actual credentials while maintaining security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A pseudo identity serves as an intermediary between the user and the shared appliance. This mediator allows the appliance to be accessed and maintained without requiring direct exposure of user credentials, solving both the security and accessibility issues simultaneously.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If full user credentials are entered at shared appliances, then access control is improved, but exposure of credentials becomes a security risk

Engineering Contradiction:
Improveaccess controlVSAvoidcredential exposure
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

Instead of using the real user identity directly, the system creates a pseudo identity that copies the necessary access functionality. This copy allows the appliance to be accessed with sufficient permissions without exposing the actual user credentials, eliminating the credential exposure risk while maintaining access control.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The pseudo identity acts as an intermediary layer that provides access control without requiring direct exposure of user credentials. The appliance interacts with the pseudo identity rather than the real user identity, preventing credential exposure while maintaining secure access control.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If print jobs are sent to distant shared printers, then resource sharing is improved, but risk of unauthorized collection increases

Engineering Contradiction:
Improveresource sharingVSAvoidunauthorized access risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system creates a pseudo identity that copies the user's printing functionality without exposing the actual user identity. This allows print jobs to be sent to distant shared printers for resource sharing while the pseudo identity protects against unauthorized collection by masking the real user's presence.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The pseudo identity acts as a protective shell around the user's printing operations. This flexible identity layer allows the print job to traverse through the shared appliance system while protecting the core user identity from exposure and unauthorized access.

Inventive Principle:
Principle #30Flexible shells and thin films

Data Source

PatentUS7856657B2Secure access of resources at shared appliances
Publication Date: 2010.12.21 WORKDAY INC
  • US7856657B2 patent drawing
  • US7856657B2 patent drawing
  • US7856657B2 patent drawing

AI summary

An exemplary method for providing secure access to resources at shared appliances comprises obtaining an instruction from a first user to send a resource to a secure repository, the resource being associated with a first identifier, receiving a second identifier from a shared appliance, determining a pseudo identity associated with the shared appliance based on the second identifier, granting to the shared appliance permissions associated with the pseudo identity, including a permission to retrieve the resource from the secure repository, receiving the first identifier from a second user at the shared appliance, and enabling the shared appliance to provide the resource to the second user at the shared appliance.