Secure Data Provisioning via Identification Session Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems for providing data to devices used by multiple users lack robust security measures, allowing unauthorized access and potential misuse, especially in shared public devices like printers.

Innovation Solution

A data providing system that includes a data providing apparatus, a data utilizing apparatus, and a communication apparatus, with features such as identification information request and output devices, session disconnection mechanisms, and storage devices to ensure secure communication and prevent unauthorized access by storing and managing identification information securely.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a device is made available for common use by multiple users, then the accessibility and utility of the device is improved, but the security risk and vulnerability to unauthorized access increases

Engineering Contradiction:
Improvedevice accessibilityVSAvoidunauthorized access risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary authentication by obtaining identification information from the communication apparatus before allowing data transmission to the data utilizing apparatus. This preliminary security check ensures that only authorized users can access the shared device, resolving the contradiction by establishing security protocols in advance while maintaining device accessibility.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The data providing apparatus acts as an intermediary between the communication apparatus and the data utilizing apparatus. It verifies identification information and controls data transmission, serving as a security mediator that enables multiple users to access the device safely through controlled authentication processes.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If identification information is transmitted and stored for authentication purposes, then the security and control capability of the system is improved, but the complexity of the authentication process increases

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication process is segmented into distinct functional components: an identification information obtaining unit that retrieves authentication data, an identification information storage unit that securely stores it, and a verification mechanism that checks it during data transmission. This segmentation makes the complex authentication process more manageable and implementable while maintaining high security standards.

Inventive Principle:
Principle #1Segmentation

3Reliability

If session management and disconnection mechanisms are implemented, then the security and fairness of shared device usage is improved, but the operational complexity and processing overhead increases

Engineering Contradiction:
Improveusage fairnessVSAvoidsession management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system implements feedback mechanisms through session disconnection management, where the data providing apparatus monitors and controls active sessions. When authentication fails or sessions expire, the system provides feedback by disconnecting inappropriate connections, ensuring fair resource distribution among users while maintaining manageable session complexity through automated control.

Inventive Principle:
Principle #23Feedback

Data Source

PatentEP2075984B1Data providing system and data providing apparatus
Publication Date: 2017.06.28 BROTHER KOGYO KK
  • EP2075984B1 patent drawingFigure 1
  • EP2075984B1 patent drawingFigure 2
  • EP2075984B1 patent drawingFigure 3

AI summary

A data providing system (2) is provided with a data providing apparatus (70), a data utilizing apparatus (10) configured to be connected with the data providing apparatus (70) in a communicable manner, and a communication apparatus (40) configured to be connected with the data providing apparatus (70) in a communicable manner. The data utilizing apparatus (10) sends an identification information-sending request (204) to the data providing apparatus (70), outputs identification information sent from the data providing apparatus (70), sends the identification information to the data providing apparatus (70), and utilizes data sent from the data providing apparatus (70). The communication apparatus (40) allows a user to input the identification information, sends the input identification information, and allows the user to disconnect a communication session with the data providing apparatus (70). The data providing apparatus (70) sends the identification information to the data utilizing apparatus (10) in accordance with the identification information-sending request (204) sent from the data utilizing apparatus (10), stores the sent identification information, and sends data to the data utilizing apparatus (10) on a condition that the identification information sent from the communication apparatus (40) is being stored, and that the identification information sent from the data utilizing apparatus (10) is received during a communication session with the communication apparatus (40).