Secure Print Policy Enforcement via Remote Attestation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing secure print policies lack assurance that sensitive documents are printed only on authorized and securely configured printers, as they do not effectively verify the security properties of printers before releasing print jobs, leaving room for unauthorized printing and data leakage.

Innovation Solution

A method that cryptographically binds a security policy to a print job, using remote attestation to verify the security properties of the printer or intermediary device, ensuring that only compliant devices can process sensitive information, and encrypts the policy with the printer's public key to prevent modification.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If existing secure print policies are used without remote attestation, then print jobs can be released quickly, but there is no assurance that printers are authorized or securely configured

Engineering Contradiction:
Improvesecurity assuranceVSAvoidpolicy verification complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent performs remote attestation verification before releasing the print job to ensure the printer is authorized and securely configured. This preliminary security check validates the printer's identity and security posture upfront, preventing unauthorized printing while maintaining a streamlined release process once verification is complete.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces a security policy verification mechanism that acts as an intermediary between the print job release and the printer. This verification layer cryptographically binds security requirements to the print job and validates the printer's attestation, providing assurance without requiring direct complex interactions between all system components.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If remote attestation verification is performed before releasing print jobs, then security assurance is improved, but the printing process time increases

Engineering Contradiction:
Improvesecurity verificationVSAvoidprint job release time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The remote attestation verification is performed as a preliminary step before print job release. By validating the printer's security posture upfront and caching the verification results, the system ensures security requirements are met while minimizing the time impact on subsequent print job releases to the same printer.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

Once a printer is verified through remote attestation, the security binding and verification results can be maintained for subsequent print jobs to that printer. This allows the security verification to be performed once rather than repeatedly for each print job, reducing time loss while maintaining continuous security assurance.

Inventive Principle:
Principle #20Continuity of useful action

3Reliability

If security policies are not cryptographically bound to print jobs, then policy modification is possible, but security integrity is compromised

Engineering Contradiction:
Improvepolicy integrityVSAvoidcryptographic binding complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies cryptographic binding to transform the security policy from a modifiable text-based configuration into a cryptographically secured structure. By signing and binding the policy to the print job using cryptographic mechanisms, the system ensures policy integrity and prevents unauthorized modification, with the cryptographic overhead being manageable through standardized implementations.

Inventive Principle:
Principle #35Parameter changes

4Reliability

If TLS with printer certificates is used, then some assurance of authorized printing is provided, but comprehensive security property verification is insufficient

Engineering Contradiction:
Improveauthorization assuranceVSAvoidsecurity policy flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent extends the security verification mechanism beyond basic TLS certificate validation to include comprehensive remote attestation that can verify multiple security properties of the printer. This multi-functional approach covers authorization, security configuration, and other policy requirements in a unified framework that works across different security scenarios and printer types.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The security policy verification system is designed to be dynamic and adaptable, allowing different security policies to be applied based on the specific print job and printer characteristics. The remote attestation mechanism can verify different security properties as needed, providing flexibility to accommodate varying organizational security requirements while maintaining a consistent verification framework.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentEP3432188B1Secure print policy enforcement
Publication Date: 2022.11.23 HEWLETT PACKARD DEVELOPMENT COMPANY LP
  • EP3432188B1 patent drawingFigure 1~4
  • EP3432188B1 patent drawingFigure 2
  • EP3432188B1 patent drawingFigure 3

AI summary

A method is described for enforcing a secure print policy, the method comprising providing a security policy, cryptographically binding the security policy to a print job to generate a secure print job, verify security properties of at least one of: a printer and an intermediary device using the security policy and a remote attestation protocol, and provided the security properties are verified, releasing the print job to the printer.