Rendezvous Server Mediates MFD Mobile VPN Setup

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional methods for establishing virtual private networks between Multi-Function Devices (MFDs) and mobile communications devices are complex, requiring extensive pre-configuration and are not user-friendly, making it difficult to achieve secure communication and control between these devices, especially when the mobile device is on a public network and the MFD is on a private enterprise network.

Innovation Solution

A method and system that uses a rendezvous server to establish a VPN connection between an MFD and a mobile communications device through a random code, such as a QR code or PIN number, displayed on the MFD's user interface, allowing the mobile device to read the code and validate the connection key, ensuring secure communication and control while preventing unwanted access by expiring the connection after inactivity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional VPN establishment methods are used between MFD and mobile device, then secure communication is achieved, but device complexity and configuration difficulty increase significantly

Engineering Contradiction:
Improvesecure communicationVSAvoidconfiguration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a rendezvous server as an intermediary component that facilitates VPN connection establishment between the mobile device and MFD. The server mediates the connection process by receiving connection requests, validating credentials, and establishing secure tunnels without requiring direct peer-to-peer configuration between the end devices. This intermediary approach simplifies the user-facing complexity while maintaining security through centralized credential management and connection oversight.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements self-service mechanisms where the mobile device automatically discovers and connects to the rendezvous server, and the system automatically establishes VPN credentials and connection parameters without requiring manual user configuration. The MFD and mobile device autonomously negotiate connection details through standardized protocols, eliminating the need for users to manually configure complex VPN settings while ensuring secure communication through automated credential validation.

Inventive Principle:
Principle #25Self-service

2Reliability

If MFD restricts access to functionality on enterprise network for security reasons, then security is improved, but ease of operation from mobile device deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidaccessibility from mobile device
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements dynamic access control where the MFD's functionality availability changes based on the established VPN connection state. When no VPN connection exists, the MFD maintains restricted access to enterprise network resources. When a validated VPN connection is established through the rendezvous server, the MFD dynamically enables additional functionality and services that were previously inaccessible. This dynamic behavior allows the system to maintain security by default while providing full functionality when properly authenticated, resolving the contradiction between security restrictions and operational accessibility.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS8842310B2Method and system for establishing secure communications between a multifunction device and a mobile communications device
Publication Date: 2014.09.23 XEROX CORP
  • US8842310B2 patent drawing
  • US8842310B2 patent drawing
  • US8842310B2 patent drawing

AI summary

A method and system for establishing secure communication between a MFD (Multi-Function Device) and a mobile communications device. A virtual private network (VPN) connection can be established between the mobile communications device and the MFD via a rendezvous server utilizing a random displayed code on a user interface of the MFD. An application with respect to the mobile communications device can be started by the user to connect to the MFD and the displayed code can be read by the mobile communications device utilizing an image capturing unit associated with the mobile communications device. The connection key presented by the mobile application can be validated by the rendezvous server. The rendezvous server can be polled for an incoming traffic and the traffic can be forwarded to a service hosted by the MFD utilizing an application running on the MFD.