Function Executing Device Secure Scan Authentication via Encrypted Paths
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing image processing devices lack secure authentication mechanisms when sending scan data to external devices, particularly when communication is unencrypted, risking unauthorized access to authentication information.
Innovation Solution
A function executing device that receives instructions from external devices, initiates an encrypted communication path to request and verify authentication information before executing a scan process, and refrains from sending authentication requests over unencrypted paths to prevent unauthorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If authentication information is requested and sent over unencrypted communication paths, then the ease of operation is improved, but security is worsened due to risk of unauthorized access
Solution Approach 1:
The patent applies local quality by differentiating communication paths based on their security characteristics. Encrypted communication paths are used for transmitting authentication information, while unencrypted paths are avoided for such sensitive data. This creates localized security zones within the communication system, ensuring that only appropriate channels are used for authentication purposes.
Solution Approach 2:
The controller acts as an intermediary that mediates between the external device and the authentication system. It intelligently selects whether to request authentication information based on the communication path type, and only processes authentication over encrypted channels. This intermediary function prevents direct exposure of authentication mechanisms to insecure environments.
2Object-affected harmful factors
If authentication information is requested over encrypted communication paths, then security is improved, but device complexity is worsened due to additional authentication management
Solution Approach 1:
The patent implements dynamics by making the authentication request behavior adaptive rather than static. The controller dynamically determines whether to send authentication information requests based on real-time detection of communication path encryption status. This dynamic adjustment allows the system to maintain security protocols only when necessary (over encrypted paths) while avoiding unnecessary complexity in unencrypted scenarios.
Solution Approach 2:
The system changes the parameter of authentication request behavior based on the encryption status of the communication path. When the path is encrypted, authentication requests are enabled; when unencrypted, they are disabled. This parameter-based control allows the system to adapt its security measures to the current communication conditions, maintaining security without imposing constant complexity.
3Productivity
If scan data is sent over unencrypted communication paths, then productivity is improved, but security is worsened due to potential data interception
Solution Approach 1:
The patent applies local quality by creating security zones for different types of data transmission. Authentication information is restricted to encrypted communication channels, while scan data can be transmitted over unencrypted paths when necessary for productivity. This localized security approach ensures that the most sensitive information (authentication credentials) receives enhanced protection while allowing less sensitive data (scan results) to flow freely when needed.
Solution Approach 2:
The system performs preliminary authentication over encrypted paths before proceeding to scan data transmission. By establishing security credentials first through secure channels, the system enables subsequent unencrypted data transmission to be protected by the previously established authentication context, allowing productivity improvements without compromising overall security.
Data Source
AI summary
A function executing device may be configured to receive a related instruction related to execution of a scan from an external device, and in a case where the related instruction is received from the external device via a first communication path for executing an encrypted communication, send an authentication information request to the external device. In a case where the related instruction is received from the external device via a second communication path for executing an unencrypted communication, the function executing device may be configured not to send the authentication information request to the external device.


