Relay Service Device Authentication for Print Systems

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing peripheral device control systems, such as those using Google Cloud Print, face issues with network traffic and load on Web service applications due to frequent communication and data exchange, particularly when dealing with inexpensive printers or multi-function peripherals that cannot render PDF files, leading to increased processing times and potential security vulnerabilities.

Innovation Solution

The implementation of a method that includes a relay service device, an intermediate service device, and an authentication service device to manage communication and authentication, reducing the frequency and quantity of data communication between Web service application devices, and using access tokens to authenticate and authorize service processing, thereby minimizing unnecessary processing and potential malicious attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If Web service applications frequently communicate and exchange data to process print jobs, then service functionality is improved, but network traffic increases and system load increases

Engineering Contradiction:
Improveservice functionalityVSAvoidnetwork traffic
Core Design Contradiction:
Adaptability or versatilityVSQuantity of substance

Solution Approach 1:

The patent applies preliminary action by having the relay service device obtain authentication information from the authentication service device in advance, before actual print job processing occurs. This pre-authentication approach allows the relay service device to verify the authenticity of execution requests without frequent real-time communication with the authentication service device, thereby reducing network traffic while maintaining service functionality.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces a relay service device as an intermediary between the authentication service device and the image conversion service device. This intermediary obtains authentication information once and uses it to verify multiple execution requests, acting as a mediator that reduces the frequency of direct communication between the authentication service device and other components,从而降低网络流量和系统负载。

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If Web service applications frequently communicate and exchange data, then service processing is enabled, but processing time increases

Engineering Contradiction:
Improveservice processing capabilityVSAvoidprocessing time
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The relay service device performs authentication in advance by obtaining authentication information from the authentication service device before actual print job execution. This pre-authentication eliminates the need for time-consuming real-time authentication queries during each print job processing, thereby reducing processing time while maintaining service processing capability.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The relay service device uses the authentication information it has obtained to independently verify the authenticity of execution requests without needing to continuously query the authentication service device. This self-verification mechanism reduces processing time by eliminating repeated authentication communication overhead.

Inventive Principle:
Principle #25Self-service

3Adaptability or versatility

If data communication between Web service application devices is increased, then service coordination is improved, but security vulnerabilities increase

Engineering Contradiction:
Improveservice coordinationVSAvoidsecurity vulnerabilities
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements preliminary authentication where the relay service device obtains authentication information in advance and uses it to verify execution requests. This approach maintains service coordination by ensuring proper authentication while reducing security vulnerabilities by minimizing the frequency of data communication with the authentication service device, thereby reducing exposure to potential security threats.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The relay service device acts as an intermediary that centralizes authentication verification. By obtaining authentication information once and using it to verify multiple requests, it reduces the attack surface and security vulnerabilities associated with frequent communication between multiple service devices and the authentication service device.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8850551B2Information processing system control method, intermediate service device, authentication method, and storage medium
Publication Date: 2014.09.30 CANON KK
  • US8850551B2 patent drawing
  • US8850551B2 patent drawing
  • US8850551B2 patent drawing

AI summary

Provided is a method for controlling an information processing system including a relay service device, an intermediate service device, and an authentication service device. The control method includes transmitting an authentication request from the intermediate service device to the intermediate service device; acquiring a first access token from the authentication service device that has made a success of authentication; storing the first access token; comparing the stored first access token with a second access token included in an execution request of an relation processing upon reception of the processing execution request from the relay service; and executing processing received from the intermediate service device when it is determined in the comparing that the first access token matches the second access token or not executing the processing when it is determined in the comparing that the first access token does not match the second access token.