IP Library Granted Patent US 12,425,855
Granted Patent B2
US 12,425,855 · App. 18/116,822 · Granted Sep 23, 2025

Performing imaging operations via a direct secure wireless connection to an imaging device

Inventor: Jacob Henry Kaplow (Seattle, WA)
Assignee: MICROSOFT TECHNOLOGY LICENSING, LLC
H04W12/069H04W12/033H04W12/08H04W12/69
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,425,855
App. No.
18/116,822
Granted
Sep 23, 2025
Kind
B2
Abstract

Technologies are disclosed for performing imaging operations via a direct secure wireless connection to an imaging device. An imaging device, such as a printer or scanner, obtains a signed certificate defining a security policy from an identity and access management (“IAM”) service. A computing device, such as a laptop or smartphone, obtains a signed certificate from the IAM service that defines access rights associated with the computing device. The imaging device and the computing device exchange the signed certificates. The imaging device approves or denies a request from the computing device to perform imaging operations by way of a direct secure wireless communication channel between the imaging device and the computing device based on the security policy and the access rights.

Claims (34)

1. A computer-implemented method, comprising:

storing a first signed certificate at an imaging device, the first signed certificate comprising a security policy for accessing functionality provided by the imaging device;

receiving a second signed certificate from the computing device at the imaging device, the second signed certificate comprising access rights for accessing the functionality provided by the imaging device;

determining, at the imaging device, to authorize the computing device to utilize the functionality provided by the imaging device by way of a direct secure wireless communication channel between the imaging device and the computing device based on the security policy and the access rights; and

based on the determining, permitting the computing device to utilize the functionality provided by the imaging device by way of the direct secure wireless communication channel.

2. The computer-implemented method of claim 1 , further comprising establishing the direct secure wireless communication channel between the imaging device and the computing device, wherein the second signed certificate is received at the imaging device during establishment of the direct secure wireless communication channel.

3. The computer-implemented method of claim 1 , further comprising establishing the direct secure wireless communication channel between the imaging device and the computing device, wherein the second signed certificate is received at the imaging device prior to establishing the direct secure wireless communication channel.

4. The computer-implemented method of claim 1 , wherein the first signed certificate further comprises a public key associated with the imaging device, and wherein the first signed certificate is signed by an identity and access management (IAM) service.

5. The computer-implemented method of claim 1 , wherein the second signed certificate further comprises a public key associated with the computing device, and wherein the second signed certificate is signed by an identity and access management (IAM) service.

6. The computer-implemented method of claim 1 , wherein the first signed certificate is stored at the imaging device when a first network connection between the imaging device and an identity and access management (IAM) service is active, wherein the second signed certificate is stored at the computing device when a second network connection between the imaging device and the IAM service is active, and wherein the second signed certificate is received from the computing device at the imaging device when the first network connection or the second network connection are not active.

7. The computer-implemented method of claim 1 , wherein the imaging device is configured to report usage and status information to a management service when an active network connection to the management service is present.

8. A computer-readable storage medium having computer-executable instructions stored thereupon which, when executed by an imaging device, cause the imaging device to:

receive a request from a computing device at an imaging device to access the functionality provided by the imaging device, the request comprising a first signed certificate that defines access rights for the computing device to access the functionality provided by the imaging device;

responsive to the request, determine, at the imaging device, to authorize the computing device to utilize the functionality provided by the imaging device by way of a direct secure wireless communication channel between the imaging device and the computing device based the access rights and a security policy contained in a second signed certificate received from the computing device; and

based on the determining, permit the computing device to utilize the functionality provided by the imaging device by way of the direct secure wireless communication channel.

9. The computer-readable storage medium of claim 8 , having further computer-executable instructions stored thereupon to obtain the first signed certificate at the imaging device during establishment of the direct secure wireless communication channel.

10. The computer-readable storage medium of claim 8 , having further computer-executable instructions stored thereupon to obtain the first signed certificate at the imaging device prior to establishing the direct secure wireless communication channel.

11. The computer-readable storage medium of claim 8 , wherein the second signed certificate further comprises a public key associated with the imaging device, and wherein the first signed certificate is signed by an identity and access management (IAM) service.

12. The computer-readable storage medium of claim 8 , wherein the first signed certificate further comprises a public key associated with the computing device, and wherein the second signed certificate is signed by an identity and access management (IAM) service.

13. The computer-readable storage medium of claim 8 , wherein the second signed certificate is obtained when the imaging device has an active network connection to an identity and access management (IAM) service, wherein the first signed certificate is obtained when the computing device has an active network connection to the IAM service, and wherein the first signed certificate is received from the computing device at the imaging device when the imaging device or the computing device do not have an active network connection to the IAM service.

14. The computer-readable storage medium of claim 8 , wherein the direct secure wireless connection comprises an ultra-wideband wireless connection between the imaging device and the computing device.

15. A system, comprising:

a processing system comprising a processor; and

a computer-readable storage medium having computer-executable instructions stored thereupon that, when executed by the processing system, cause the system to:

obtain a first signed certificate defining a security policy for accessing functionality provided by an imaging device;

obtain a second signed certificate defining access rights for a computing device to access the functionality provided by the imaging device;

receive a request from the computing device at the imaging device to access the functionality provided by the imaging device;

responsive to the request, determine, at the imaging device, whether to authorize the computing device to utilize the functionality provided by the imaging device by way of a direct secure wireless communication channel between the imaging device and the computing device based on the security policy and the access rights; and

based on the determining, permit the computing device to utilize the functionality provided by the imaging device by way of the direct secure wireless communication channel.

16. The processing system of claim 15 , wherein the direct secure wireless connection comprises an ultra-wideband wireless connection between the imaging device and the computing device.

17. The processing system of claim 16 , wherein the computer-readable storage medium has further computer-executable instructions stored thereupon to obtain the second signed certificate at the imaging device during establishment of the direct secure wireless communication channel.

18. The processing system of claim 16 , wherein the computer-readable storage medium has further computer-executable instructions stored thereupon to obtain the second signed certificate at the imaging device prior to establishing the direct secure wireless communication channel.

19. The processing system of claim 15 , wherein the first signed certificate and the second signed certificate are signed by an identity and access management (IAM) service.

20. The processing system of claim 15 , wherein the computer-readable storage medium has further computer-executable instructions stored thereupon to report usage and status information to a management service when no active network connection from the imaging device to a management service is present.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 6, 2023
From: KAPLOW, JACOB HENRY
To: MICROSOFT TECHNOLOGY LICENSING, LLC
Reel/Frame 062891/0584 →
Continuity (1)
Related Publication 20240298177A1 · Sep 5, 2024
References Cited (18)
US 9230125B2 · Inoue · 2016 [cited by applicant]
US 10742831B1 · Haapanen · 2020 [cited by applicant]
US 11425767B2 · Foster et al. · 2022 [cited by applicant]
US 20070242729A1 · Quinn et al. · 2007 [cited by applicant]
US 20110075186A1 · Azuma · 2011 [cited by applicant]
US 20130057895A1 · Okazawa · 2013 [cited by applicant]
US 20130061041A1 · Inoue · 2013 [cited by examiner]
US 20130067543A1 · Takeda · 2013 [cited by examiner]
US 20130141747A1 · Oba et al. · 2013 [cited by applicant]
US 20130201515A1 · Daos et al. · 2013 [cited by applicant]
US 20140240753A1 · Anno · 2014 [cited by examiner]
US 20180278607A1 · Loladia · 2018 [cited by applicant]
US 20200267006A1 · Nyman · 2020 [cited by examiner]
US 20220095108A1 · Siedow · 2022 [cited by examiner]
Torrellas et al, An Authentication Protocol for Agent Platform Security Manager, Sep. 19, 2003, IEEE, pp. 623-628. (Year: 2003). [cited by examiner]
Markopoulos et al, Security Mechanisms Maintaining User Profile in a Personal Area Network, Sep. 10, 2003, pp. 2770-2774. (Year: 2003). [cited by examiner]
International Search Report and Written Opinion received for PCT Application No. PCT/US2024/017191 May 31, 2024, 15 pages. [cited by applicant]
“Universal Print”, Retrieved From: https://web.archive.org/web/20221117033107/https://www.microsoft.com/en-us/microsoft-365/windows/universal-print, Retrieved Date: Nov. 17, 2022, 7 Pages. [cited by applicant]