Direct Secure Wireless Imaging with Signed Certificate Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In secure imaging environments, transmitting documents over the internet twice for imaging operations is inefficient and can be problematic due to slow or unreliable connections, and existing direct communication mechanisms lack security enforcement and management functionality.

Innovation Solution

Implementing a direct secure wireless connection between imaging devices and computing devices using signed certificates from an Identity and Access Management (IAM) service, allowing local authentication and policy enforcement without internet connectivity, thus eliminating the need for double document transmission.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If documents are transmitted over the internet twice for imaging operations, then authentication and policy enforcement are achieved, but network bandwidth usage increases and operation reliability decreases

Engineering Contradiction:
Improveoperation reliabilityVSAvoidnetwork bandwidth usage
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The system performs authentication and policy enforcement actions in advance by establishing a secure direct connection before document transmission. The imaging device and computing device mutually authenticate using digital certificates and security policies are evaluated beforehand, allowing subsequent document operations to proceed reliably without repeated internet transmissions.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces a secure direct wireless connection as an intermediary communication channel between the imaging device and computing device. This intermediary channel, established through mutual authentication and secured by signed security policies, eliminates the need for double internet transmission while maintaining authentication reliability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Loss of energy

If direct communication mechanism is used between imaging devices and computing devices, then network bandwidth usage is reduced, but security enforcement and policy management functionality are lost

Engineering Contradiction:
Improvenetwork bandwidth usageVSAvoidsecurity enforcement
Core Design Contradiction:
Loss of energyVSReliability

Solution Approach 1:

Security policies are signed and stored in advance by the imaging device before direct communication occurs. The computing device presents its credentials beforehand, allowing the imaging device to evaluate security policies and enforce authentication rules before document transmission begins, thus maintaining security without repeated internet connections.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The imaging device autonomously performs security enforcement by locally storing and evaluating signed security policies. The device independently authenticates computing devices and enforces policies without requiring continuous internet connectivity or remote authentication service, enabling self-contained secure operation.

Inventive Principle:
Principle #25Self-service

3Reliability

If imaging operations require internet connectivity for authentication, then policy enforcement is maintained, but operational flexibility and reliability in disconnected environments are reduced

Engineering Contradiction:
Improvepolicy enforcementVSAvoidoperational flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

Authentication credentials and security policies are prepared and stored in advance on the imaging device before disconnection occurs. When internet connectivity is unavailable, the device can still perform imaging operations by using pre-stored signed security policies and mutual authentication mechanisms, maintaining both policy enforcement and operational flexibility.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The imaging device becomes self-sufficient by storing signed security policies and authentication credentials locally. This enables the device to autonomously enforce policies and authenticate computing devices without requiring continuous internet connectivity, thereby adapting to both connected and disconnected environments.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12452666B2Performing imaging operations via a direct secure wireless connection to an imaging device
Publication Date: 2025.10.21 MICROSOFT TECHNOLOGY LICENSING LLC
  • US12452666B2 patent drawing
  • US12452666B2 patent drawing
  • US12452666B2 patent drawing

AI summary

Technologies are disclosed for performing imaging operations via a direct secure wireless connection to an imaging device. An imaging device, such as a printer or scanner, obtains a signed certificate defining a security policy from an identity and access management (“IAM”) service. A computing device, such as a laptop or smartphone, obtains a signed certificate from the IAM service that defines access rights associated with the computing device. The imaging device and the computing device exchange the signed certificates. The imaging device approves or denies a request from the computing device to perform imaging operations by way of a direct secure wireless communication channel between the imaging device and the computing device based on the security policy and the access rights.