Spatial-Temporal Limited User Sessions for Secure Appliance Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing appliances, such as printers, do not allow remote access and secure sharing of confidential outputs, limiting user convenience and security in shared resource environments.

Innovation Solution

A spatial-temporal limited user session system that enables a server to bridge user and appliance databases, allowing secure access to user data without direct integration, using a communications-enabled device to authenticate and authorize access to target appliances without requiring user login on each device.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If appliances share resources to reduce support and maintenance, then resource utilization efficiency is improved, but security and confidentiality of user data deteriorates

Engineering Contradiction:
Improveresource utilization efficiencyVSAvoidsecurity and confidentiality
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent introduces a user session as an intermediary mechanism between the user and the shared appliance. This session acts as a mediator that grants temporary, authenticated access to the appliance without exposing user credentials or allowing persistent access. The session includes authentication data that verifies user identity and authorization level, enabling secure resource sharing while maintaining confidentiality through time-limited, authenticated connections.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If appliances allow remote access for user convenience, then ease of operation is improved, but security control deteriorates

Engineering Contradiction:
Improveremote access convenienceVSAvoidsecurity control
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements dynamic session management where user sessions are created, maintained, and terminated based on real-time conditions. The system dynamically establishes sessions when users need remote access, maintains them during active use, and automatically terminates them when no longer needed or when security conditions change. This dynamic approach enables convenient remote access while maintaining security control through adaptive session lifecycle management.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system employs periodic session validation and time-limited session duration. User sessions are granted for specific time periods and require periodic verification of continued authorization. This periodic action allows remote access convenience during valid session periods while maintaining security control through automatic expiration and renewal mechanisms.

Inventive Principle:
Principle #19Periodic action

3Adaptability or versatility

If user sessions are shared across multiple devices, then adaptability is improved, but tracking and control difficulty increases

Engineering Contradiction:
Improvecross-device access flexibilityVSAvoidsession tracking complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent creates session copies that can be transferred between different user devices. When a user logs in from a new device, the system generates a session copy with appropriate authentication data for that device, rather than requiring the user to manually configure access on each device. This copying mechanism enables cross-device adaptability while simplifying tracking, as the system manages session replication centrally rather than requiring complex peer-to-peer device coordination.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS11477294B2Spatial-temporal limited user sessions
Publication Date: 2022.10.18 HEWLETT PACKARD DEVELOPMENT COMPANY LP
  • US11477294B2 patent drawing
  • US11477294B2 patent drawing
  • US11477294B2 patent drawing

AI summary

A method comprises receiving, at a server from a communications-enabled device that includes processing circuitry, a request for providing a user session correlated with a user identifier (ID) and a target appliance. The method further includes in response to the request for the requested user session: retrieving a user attribute from a user-ID database that stores user ID information for a plurality of user accounts, and retrieving an appliance attribute from an appliance-ID database that stores appliance ID information; and correlating the retrieved user attribute and appliance attribute with the requested user session for a user account from among the plurality of user accounts. The method further includes transferring the requested user session to the target appliance as a new user session that is spatial-temporal limited and that is without the target appliance using user login information.