Script Execution Authentication in Image Processing Apparatus

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Image processing apparatuses are vulnerable to hacking attacks, where hackers alter data codes executed on the OS, leading to data leakage or system damage, necessitating enhanced security measures for script data execution.

Innovation Solution

An image processing apparatus with a storage system that includes an operating system, a script file with program code and a first electronic signature, and an interpreter program, which performs authentication on the electronic signature before allowing or blocking the execution of the program code, using algorithms like hash functions and encryption to ensure security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If the image processing apparatus executes script data without authentication, then the ease of operation is improved, but the security is worsened

Engineering Contradiction:
Improveease of operationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent applies preliminary action by performing electronic signature authentication on script data before execution. The authentication process verifies the integrity and legitimacy of the script data in advance, preventing unauthorized or malicious code from being executed. This resolves the contradiction by maintaining ease of operation for legitimate scripts while ensuring security through pre-execution verification.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary authentication mechanism between the script data and the execution environment. The electronic signature verification acts as a mediator that checks the legitimacy of script data without requiring users to manually verify each script, thus maintaining ease of operation while ensuring security through automated verification.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If the image processing apparatus implements signature authentication for script data, then the security is improved, but the device complexity is worsened

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies self-service by making the authentication process automatic and self-verifying. The script data carries its own electronic signature, and the authentication mechanism automatically verifies this signature without requiring external intervention or complex manual verification procedures. This reduces device complexity by automating the security check rather than requiring complex external verification systems.

Inventive Principle:
Principle #25Self-service

3Reliability

If the image processing apparatus authenticates electronic signatures, then the security is improved, but the processing time is worsened

Engineering Contradiction:
ImprovesecurityVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies partial action by performing only the essential authentication check (electronic signature verification) rather than comprehensive security analysis. This partial verification approach provides sufficient security for script execution while minimizing the time overhead, as it focuses only on verifying the signature rather than analyzing the entire script content.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS10382207B2Image processing apparatus and control method thereof
Publication Date: 2019.08.13 SAMSUNG ELECTRONICS CO LTD
  • US10382207B2 patent drawing
  • US10382207B2 patent drawing
  • US10382207B2 patent drawing

AI summary

An image processing apparatus is provided. The image processing apparatus includes a storage configured to store an operating system (OS) of the image processing apparatus, a script file including a program code and a first electronic signature, and an interpreter program provided to execute the program code on the OS; and at least one processor configured to perform an authentication of the first electronic signature with the OS in response to the interpreter program executing the program code on the OS, and selectively permit or block the execution of the program code according to whether the first electronic signature passes or fails to pass the authentication.