MFP Walkup Functions Control

MFP Walkup Functions Control

Description

SafeQ Terminal blocks access to the MFP panel options so only authenticated and authorized user can operate it.

User Stories

  1. AuthCopy - As a User I want to authenticate at the MFP so that the MFP knows my identity and can provide personalized workflow based on my needs.

Requirements

  • SafeQ shall block copy access when user doesn't have proper permissions.

  • SafeQ shall block colour copy if user doesn't have proper permissions to print in colour.

  • SafeQ shall stop hard copy after first detected colour copy if user doesn't have proper permissions to print in colour.

  • Administrator shall be able to define timeout for user's session (after what time is user logged off at the device when idle).

Special Requirements

In addition to the standard terminal access control, SafeQ shall control copy access to any Xerox Network Accounting JBA enabled networked printer via Network Accounting Kit (JBA):

  • Copy jobs must be authenticated via JBA on-box (On-Box mode is not supported on ORS servers and must be configured centrally) or off-box mode by: Login/PIN, Login only, PIN only.

  • Special license might be required.

  • When using JBA on-box mode, all PIN codes must be stored in DB in unencrypted form, so it can be transferred to the device. Number of users account that can be stored to the device differs depends on device available memory.

  • Both HTTP and HTTPS communication protocols are supported for JBA.

Dependencies/non-functional requirements

  • YSoft SafeQ Server must be installed and available within LAN proximity.

  • Identity management must be established.

  • MFP must be equipped with terminal with correctly configured authentication and support panel access control.

Caveats

  • Due to the technical limitations, color copy blocking and Real-Time hard copy stop is only supported by Terminal Professional/Ultralight using Xerox FDI,KM Vender2 interfaces,KM OpenAPI, Ricoh ESA and Xerox EIP 2.0 capable devices.

Terminal Authentication and Access Control overview

Authentication Function

Terminal Professional

Terminal UltraLight

Terminal Embedded

PIN code (see YSoft SafeQ Security Overview for more details)

images/s/-3eliqb/8502/404359a7d2ab19c9c7c58d12013124a386b28257/_/images/icons/emoticons/check.svg

images/s/-3eliqb/8502/404359a7d2ab19c9c7c58d12013124a386b28257/_/images/icons/emoticons/check.svg

images/s/-3eliqb/8502/404359a7d2ab19c9c7c58d12013124a386b28257/_/images/icons/emoticons/check.svg see Embedded Terminals

Login / password credentials (see YSoft SafeQ Security Overview for more details)

images/s/-3eliqb/8502/404359a7d2ab19c9c7c58d12013124a386b28257/_/images/icons/emoticons/check.svg

images/s/-3eliqb/8502/404359a7d2ab19c9c7c58d12013124a386b28257/_/images/icons/emoticons/error.svg

images/s/-3eliqb/8502/404359a7d2ab19c9c7c58d12013124a386b28257/_/images/icons/emoticons/check.svg see Embedded Terminals

Proximity cards with support for Use Card Number Conversion (Please contact Y Soft customer support for details about supported technologies)

images/s/-3eliqb/8502/404359a7d2ab19c9c7c58d12013124a386b28257/_/images/icons/emoticons/check.svg

images/s/-3eliqb/8502/404359a7d2ab19c9c7c58d12013124a386b28257/_/images/icons/emoticons/check.svg

images/s/-3eliqb/8502/404359a7d2ab19c9c7c58d12013124a386b28257/_/images/icons/emoticons/check.svg see Embedded Terminals

Contact cards (Please contact Y Soft customer support for details about supported technologies)

  • Magnetic swipe-thru cards (with PIN code confirmation and support for Use Card Number Conversion)

  • Barcodes via laser beam images/s/-3eliqb/8502/404359a7d2ab19c9c7c58d12013124a386b28257/_/images/icons/emoticons/warning.svg not supported on most of the Embedded Terminals

  • iButton (Dallas)

images/s/-3eliqb/8502/404359a7d2ab19c9c7c58d12013124a386b28257/_/images/icons/emoticons/check.svg

images/s/-3eliqb/8502/404359a7d2ab19c9c7c58d12013124a386b28257/_/images/icons/emoticons/error.svg

images/s/-3eliqb/8502/404359a7d2ab19c9c7c58d12013124a386b28257/_/images/icons/emoticons/check.svg see Embedded Terminals

Contact smart cards with PIN code confirmation and User (certificate-based) authentication via Kerberos v5 PKINIT
images/s/-3eliqb/8502/404359a7d2ab19c9c7c58d12013124a386b28257/_/images/icons/emoticons/warning.svg Due to very loose interpretation of the standard, YSoft internal testing, re-configuration or customization is necessary. See Smart Card support for configuration details
Please contact Y Soft customer support for details about supported technologies

images/s/-3eliqb/8502/404359a7d2ab19c9c7c58d12013124a386b28257/_/images/icons/emoticons/check.svg

images/s/-3eliqb/8502/404359a7d2ab19c9c7c58d12013124a386b28257/_/images/icons/emoticons/error.svg

images/s/-3eliqb/8502/404359a7d2ab19c9c7c58d12013124a386b28257/_/images/icons/emoticons/error.svg

FIPS 201 PIV Card / PIV II CAC Card - see http://csrc.nist.gov/groups/SNS/piv/index.html

images/s/-3eliqb/8502/404359a7d2ab19c9c7c58d12013124a386b28257/_/images/icons/emoticons/check.svg

images/s/-3eliqb/8502/404359a7d2ab19c9c7c58d12013124a386b28257/_/images/icons/emoticons/error.svg

images/s/-3eliqb/8502/404359a7d2ab19c9c7c58d12013124a386b28257/_/images/icons/emoticons/error.svg

Card self-assignment via Card Activation Code (see Card self-assignment)

images/s/-3eliqb/8502/404359a7d2ab19c9c7c58d12013124a386b28257/_/images/icons/emoticons/check.svg

images/s/-3eliqb/8502/404359a7d2ab19c9c7c58d12013124a386b28257/_/images/icons/emoticons/check.svg

images/s/-3eliqb/8502/404359a7d2ab19c9c7c58d12013124a386b28257/_/images/icons/emoticons/check.svg see Embedded Terminals

Card self-assignment via user credentials (see Card self-assignment)

images/s/-3eliqb/8502/404359a7d2ab19c9c7c58d12013124a386b28257/_/images/icons/emoticons/check.svg

images/s/-3eliqb/8502/404359a7d2ab19c9c7c58d12013124a386b28257/_/images/icons/emoticons/error.svg

images/s/-3eliqb/8502/404359a7d2ab19c9c7c58d12013124a386b28257/_/images/icons/emoticons/check.svg see Embedded Terminals