Enhanced authentication method and system

A cache-based authentication system on MFPs speeds up user login by local comparison and token use, addressing slow authentication issues in multifunction peripherals.

JP7758773B2Active Publication Date: 2025-10-22KONICA MINOLTA BUSINESS SOLUTIONS USA INC
View PDF 8 Cites 0 Cited by

Patent Information

Application Number
JP2024036683
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Priority Date
2023-03-31
Filing Date
2024-03-11
Publication Date
2025-10-22
Estimated Expiration
2044-03-11

AI Technical Summary

Technical Problem

Authentication methods for multifunction peripherals (MFPs) often require software updates and take longer than desired, especially with biometric and multi-factor authentication, leading to slower login times.

Method used

Implementing a cache on the MFP to store a list of authorized users, allowing for faster authentication by comparing user information locally and using an authentication token when necessary, reducing the need for communication with external systems.

Benefits of technology

Enhances authentication speed by eliminating multiple hops to an authentication system, providing quicker login times and improved user access to MFPs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007758773000001
    Figure 0007758773000001
  • Figure 0007758773000002
    Figure 0007758773000002
  • Figure 0007758773000003
    Figure 0007758773000003
Patent Text Reader

Abstract

To provide a strengthened authentication time method and a system for speeding up a login.SOLUTION: A method includes: receiving authentication information from a client device on a computer system; comparing the authentication information received from the client device with authentication information within a list of permitted users hosted in a cache of the computer system; and, when the authentication information received from the client device matches authentication information associated with the user within the list of the permitted user in the cache of the computer system, authenticating the user about access to the computer system.SELECTED DRAWING: Figure 5
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present disclosure relates generally to methods and systems for enhanced authentication, and more particularly to methods and systems for enhanced authentication time of users on multifunction peripherals or multifunction printers (MFPs) with faster login. [Background technology]

[0002] Multifunction peripherals or multifunction printers (MFPs) often require users to log in to implement a managed print service (MPS). Managed print services can include, for example, user authentication to control user identity and help ensure users are authenticated to the MFP before a print job is released and / or printed. Additionally, managed print services allow administrators to track and monitor usage in real time through periodic, scheduled, and on-demand reporting, management, and cost chargeback by assigning users to cost centers and entering billing or project codes before printing documents. Managed print services also allow for the creation of printing rules and policies, ensuring cost control by, for example, allowing different user roles to access different devices and features. For example, double-sided and / or color printing may be permitted for certain individuals and / or groups but not others. Summary of the Invention [Problem to be solved by the invention]

[0003] As authentication methods are added, such as using biometric identifiers to access multifunction peripherals and multifunction printers (MFPs), the MFP must support each authentication method, which may require software updates, etc. Also, authentication times for biometric and multi-factor authentication are often longer than desired or expected. [Means for solving the problem]

[0004] Therefore, it would be desirable to have an enhanced authentication time method and system for speeding up login by creating a list of users that is cached on the MFP rather than an authentication system not hosted on the MFP and can provide multiple users to be authenticated by the MFP. Additionally, the enhanced authentication time method and system can, for example, create a cache list for users in the vicinity of a particular MFP, which can provide faster login time because, for example, communication over multiple or multiple hops to an authentication system can be eliminated and a single cache can provide authentication including an authentication token to authenticate the user.

[0005] Considering the above issues, it is desirable to have a method or mechanism to improve the speed of user authentication by utilizing a company-wide infrastructure that speeds up logins, such as access to multi-function peripherals and multi-function printers (MFPs).

[0006] According to one aspect, a method of enhanced authentication includes receiving authentication information from a client device on a computer system; comparing the authentication information received from the client device to authentication information in a list of authorized users hosted in a cache of the computer system; and authenticating the user for access to the computer system if the authentication information received from the client device matches authentication information associated with a user in the list of authorized users in the cache of the computer system. and, if the authentication information received from the client device is not associated with the user in the list of authorized users in the cache of the computer system, forwarding the authentication information to an authentication server by the computer system; when the authentication server authenticates the authentication information, receiving, by the computer system, an authentication token for the user from the authentication server; and, upon receiving the authentication token for the user from the authentication server, storing the authentication information of the user in the list of authorized users in the cache of the computer system. . The method for enhanced authentication also includes receiving authentication information from a client device on a computer system; comparing the authentication information received from the client device with authentication information in a list of authorized users hosted in a cache of the computer system; and authenticating the user for access to the computer system if the authentication information received from the client device matches authentication information associated with a user in the list of authorized users in the cache of the computer system, and further includes receiving by the computer system from an external server the list of authorized users to be stored in the cache of the computer system, the list of authorized users including an authentication sequence for the user to be stored in the cache of the computer system. Further, a method of enhanced authentication includes receiving authentication information from a client device on a computer system; comparing the authentication information received from the client device to authentication information in a list of authorized users hosted in a cache of the computer system; and authenticating the user for access to the computer system if the authentication information received from the client device matches authentication information associated with a user in the list of authorized users in the cache of the computer system, wherein the authentication information from the client device to the computer system is the same authentication information used by the user to access the client device, and the same authentication information is at least one of a biometric identifier or multi-factor authentication. .

[0007] According to another aspect, a computer program for accessing a multifunction peripheral device, the computer program having program instructions executable by a computer, the program instructions including: receiving authentication information from a client device on the computer; comparing the authentication information received from the client device with authentication information in a list of authorized users hosted in a cache of the computer; and authenticating the user for access to the computer if the authentication information received from the client device matches authentication information associated with a user in the list of authorized users in the cache of the computer. and, if the authentication information received from the client device is not associated with the user in the list of authorized users in the cache of the computer, forwarding the authentication information to an authentication server by the computer; receiving, by the computer, an authentication token for the user from the authentication server when the authentication server authenticates the authentication information; and storing the authentication information of the user in the list of authorized users in the cache of the computer upon receiving the authentication token for the user from the authentication server. Run the process. Also, a computer program for accessing a multifunction peripheral device, having program instructions executable by a computer, the program instructions causing the computer to perform a process comprising: receiving authentication information from a client device on the computer; comparing the authentication information received from the client device with authentication information in a list of authorized users hosted in a cache of the computer; and authenticating the user for access to the computer if the authentication information received from the client device matches authentication information associated with a user in the list of authorized users in the cache of the computer; and further comprising receiving by the computer from an external server the list of authorized users to be stored in the cache of the computer, the list of authorized users including an authentication sequence for the user to be stored in the cache of the computer. Further, a computer program for accessing a multifunction peripheral device, the computer program having program instructions executable by a computer, the program instructions causing the computer to perform a process comprising: receiving authentication information from a client device on the computer; comparing the authentication information received from the client device with authentication information in a list of authorized users hosted in a cache of the computer; and authenticating the user for access to the computer if the authentication information received from the client device matches authentication information associated with a user in the list of authorized users in the cache of the computer, wherein the authentication information from the client device to the computer is the same authentication information the user uses to access the client device, the same authentication information being at least one of a biometric identifier or multi-factor authentication.

[0008] According to a further aspect, a multifunction peripheral device includes a cache and a processor, wherein the processor receives authentication information from a client device, compares the authentication information received from the client device with authentication information in a list of authorized users hosted in the cache of the multifunction peripheral device, and, if the authentication information received from the client device matches the authentication information associated with a user in the list of authorized users in the cache of the multifunction peripheral device, authenticates the user for access to the multifunction peripheral device. and if the authentication information received from the client device is not associated with the user in the list of authorized users in the cache of the multifunction peripheral, forwarding the authentication information to an authentication server by the multifunction peripheral; receiving, by the multifunction peripheral, an authentication token for the user from the authentication server when the authentication server authenticates the authentication information; and storing, by the multifunction peripheral, the authentication information for the user in the list of authorized users in the cache of the multifunction peripheral upon receiving the authentication token for the user from the authentication server. It is configured to: The multifunction peripheral device also includes a cache and a processor, wherein the processor receives authentication information from a client device, compares the authentication information received from the client device with authentication information in a list of authorized users hosted in the cache of the multifunction peripheral, and if the authentication information received from the client device matches the authentication information associated with a user in the list of authorized users in the cache of the multifunction peripheral, authenticates the user for access to the multifunction peripheral, and further includes receiving by the multifunction peripheral from an external server the list of authorized users to be stored in the cache of the multifunction peripheral, wherein the list of authorized users is configured to include an authentication sequence for the user to be stored in the cache of the multifunction peripheral. The multifunction peripheral further comprises a cache and a processor, wherein the processor is configured to receive authentication information from a client device, compare the authentication information received from the client device with authentication information in a list of authorized users hosted in the cache of the multifunction peripheral, and if the authentication information received from the client device matches the authentication information associated with a user in the list of authorized users in the cache of the multifunction peripheral, authenticate the user for access to the multifunction peripheral, wherein the authentication information from the client device to the multifunction peripheral is the same authentication information used by the user to access the client device, and wherein the same authentication information is at least one of a biometric identifier or multi-factor authentication.

[0009] It is to be understood that both the foregoing general description and the following detailed description are exemplary and explanatory and are intended to provide further explanation of the invention as claimed. [Brief explanation of the drawings]

[0010] The accompanying drawings are included to provide a further understanding of the invention, and are incorporated in and constitute a part of this specification. The drawings illustrate embodiments of the invention and, together with the description, serve to explain the principles of the invention. [Figure 1] FIG. 1 is a diagram of a system for authenticating a user on a computer system in accordance with an exemplary embodiment. [Figure 2] FIG. 2 is a diagram of another system for user authentication on a computer system according to an embodiment. [Figure 3] FIG. 3 is an illustration of an infrastructure for authenticating a user according to an example embodiment. [Figure 4] FIG. 4 is an illustration of a flow for authenticating a user according to an example embodiment. [Figure 5] FIG. 5 is a flow chart of a method for enhanced authentication of a user according to one embodiment. [Figure 6] FIG. 6 is an exemplary diagram of the hardware architecture of an embodiment of a computer system. DETAILED DESCRIPTION OF THE INVENTION

[0011] DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS A preferred embodiment of the present invention will now be described in detail with reference to the accompanying drawings, in which: Wherever possible, the same reference numbers are used in the drawings and the description to refer to the same or like parts.

[0012] 1 is a diagram of a system 100 for authenticating a user 102 on a computer system 110 according to an example embodiment. As shown in FIG. 1, the system 100 may include a computer system 110, e.g., a multifunction peripheral or multifunction printer (MFP) 112, and one or more computer systems 120, 130, which may be configured to host, for example, one or more managed print services (MPS) 124, 134. The one or more managed print services 124, 134 may be hosted on one or more servers 122, 132, which may include, for example, a cloud server 122.

[0013] System 100 may also include user 102 and a client device 140 capable of authenticating user 102 for access to, for example, computer system 110 as disclosed herein. According to one embodiment, client device 140 may be, for example, a mobile client, such as a smartphone, smart tablet, smart watch, or biometric band that may be used as an authentication device for, for example, authenticating user 102 on computer system 110. Authentication of user 102 on computer system 110 may be, for example, a FIDO authentication workflow for accessing computer system 110, such as a multifunction peripheral or multifunction printer 112, and managed print services 124, 134 that may be hosted on computer systems 120, 130. Computer system 110 may be configured to receive communications from client device 140 via, for example, near-field communication (NFC) or Bluetooth protocols.

[0014] One or more of the computer systems 110, 120, 130 and the client device 140 may include a processor or central processing unit (CPU) and one or more memories for storing software programs and data. The processor or CPU executes instructions of the computer programs and operates and / or controls at least a portion of the device functionality of the one or more of the computer systems 110, 120, 130 and the client device 140. One or more of the computer systems 110, 120, 130 and the client device 140 may also include an operating system (OS) that manages the computer hardware and provides common services for efficiently running various software programs. For example, the software programs may include application software for managing authentication modules and / or biometric identifiers, and / or printer driver software for one or more of the computer systems 110, 120, 130, such as the computer system 110, for example, and for one or more of the computer systems 110, 120, 130, such as the multifunction peripheral or multifunction printer 112, for example.

[0015] According to one embodiment, computer system 110 may be a multifunction peripheral or multifunction printer (MFP) 112 and may include at least copy, image reading, facsimile (FAX), and printer functions, e.g., capable of forming images on sheets based on print job multifunction peripheral (print instructions) received from computer system 110. Multifunction peripheral or multifunction printer 112 preferably includes a cache 150, which hosts the identities of one or more users 102 who may be authenticated, e.g., while in the vicinity of one or more multifunction peripherals or multifunction printers 112 as disclosed herein.

[0016] For example, computer system 110 may be a medical device or equipment, e.g., capable of being used for diagnostic and / or therapeutic purposes. Examples of medical devices or equipment may include medical imaging equipment capable of obtaining, e.g., radiographic, angiographic, ultrasound, and / or tomographic images. Alternatively, one or more of computer systems 110, 120, 130, e.g., computer systems 120, 130, may be, e.g., back-end or enterprise database systems, accessible by one or more users indirectly through, e.g., an external application via computer system 110.

[0017] According to one embodiment, when the computer system 110 is a multifunction peripheral or multifunction printer (MFP) 112, one or more of the computer systems 120, 130 can be configured to host, for example, a managed print service (MPS) 124, 134. The managed print service 124, 134 can include, for example, one or more of user authentication, monitoring and reporting, user and cost management, cost accounting and budget management, printer queue management, and workflow management. For example, user authentication can include control over a user's identity and help ensure that a user is authenticated to a device before a print job is released and / or printed. The monitoring and reporting functionality allows administrators to track and monitor usage in real time through periodic, scheduled, and on-demand reports. The user and cost management functionality helps with management and chargeback by allowing users to be assigned to cost centers and to select the associated cost center, billing, or project code before printing a document. Additionally, user and cost management features can be used to create printing rules and policies, allowing different user roles to access different devices and features, ensuring tighter cost control. For example, user and cost management can control, for example, double-sided and / or color printing for individuals and / or groups. Furthermore, cost accounting and budget management can be used as a print management solution, providing cost control and flexibility, with administrators having the option to allocate printing budgets to users and charge their accounts. For example, in a university environment, administrators can provide students with free printing quotas and add more as needed. And print queue management can be used to manage individual production in addition to office print queues, for example.

[0018] One or more computer systems 110, 120, 130 and client device 140 can be connected via a communications network 160. Communications network 160 may include, for example, a conventional network, either wired or wireless, and may have any number of configurations, such as a star configuration, a token ring configuration, or other known configurations. Communications network 160 may include one or more local area networks (LANs), wide area networks (WANs) (such as the Internet), virtual private networks (VPNs), peer-to-peer networks, near-field networks (such as Bluetooth®), cellular networks (such as 3G, 4G, 5G, or other generations), and / or other interconnected data paths over which multiple computing nodes may communicate.

[0019] Data may be transferred in encrypted or unencrypted form between one or more computer systems 110, 120, 130 and client device 140 using a variety of different communication protocols, including, for example, various internet-layer, transport-layer, or application-layer protocols. For example, data may be transferred between one or more computer systems 110, 120, 130 and client device 140 over network 160 using Transmission Control Protocol / Internet Protocol (TCP / IP), User Datagram Protocol (UDP), Transmission Control Protocol (TCP), Hypertext Transfer Protocol (HTTP), Secure Hypertext Transfer Protocol (HTTPS), Dynamic Adaptive Streaming over HTTP (DASH), Real-Time Streaming Protocol (RTSP), Real-Time Transport Protocol (RTP) and Real-Time Transport Control Protocol (RTCP), File Transfer Protocol (FTP), WebSocket (WS), Wireless Access Protocol (WAP), various messaging protocols (SMS, MMS, XMS, IMAP, SMTP, POP, WebDAV, etc.), or other known protocols.

[0020] As shown in FIG. 1 , user 102 can present an authenticator to computer system 110. Authentication of user 102 on computer system 110 can be via client device 140, for example, via near-field communication (NFC) or Bluetooth. For example, user 102 can be authenticated on client device 140, which can be a security identification and authentication device (or authenticator) that uses automated methods to verify or recognize the identity of a living person, for example, based on physiological or behavioral characteristics. Thus, the user does not need to manually enter a password into computer system 110, for example, a multifunction peripheral or multifunction printer 112. Methods for recognizing user 102 can include, for example, fingerprints, electrocardiogram (ECG or EKG) information, facial images, irises, and voice recognition. For example, according to an exemplary embodiment, the client device 140 may be a wearable device, such as a Nymi® band, and detection of the user 102 is based on an electrocardiogram (ECG) and its inherent characteristics, such as the electrical activity of the user's (e.g., wearer's) 102 heartbeat.

[0021] For example, authentication via client device 140 may include presenting user 102's mobile device, smartphone, or smartwatch in proximity to an authenticator (e.g., client device 140), e.g., via a near field communication (NFC) network (e.g., Bluetooth), where user 102 has previously authenticated on the mobile device or smartphone by one or more of a user identifier (ID) and password and / or biometric authentication, e.g., facial recognition, fingerprint, etc.

[0022] According to an example embodiment, authentication of a user 102 on a client device 140 may include a biometric identifier, which is a distinctive, measurable characteristic used to label, describe, or identify an individual, including metrics related to human characteristics. For example, a biometric identifier may include an individual's physiological characteristics (including, but not limited to, fingerprints, palm veins, facial recognition, DNA (i.e., deoxyribonucleic acid), palm print, hand geometry, iris recognition, retina, and / or scent / scent).

[0023] 2 is a diagram of another system 200 for user authentication on a computer system 110, according to an embodiment. As shown in FIG. 2, the system 200 may include one or more computer systems 110, for example, in the form of a multifunction peripheral or multifunction printer (MFP) 112, that can authenticate a user 102 via a list of authenticated users for each of the one or more computer systems 110. For example, the list of authenticated users 102 for each of the one or more computer systems 110 may be cache lists 150, 152 hosted by the one or more computer systems 110. According to one embodiment, the cache lists 150, 152 of authenticated users 102 may be different for each of the one or more computer systems 110. Additionally, the cache lists 150, 152 may be encrypted cache lists, for example.

[0024] For example, according to one embodiment, a user 102 may access one or more computer systems 110 via a mobile application that authenticates the user on a mobile device 140 via an authentication protocol. The user 102 may be authenticated, for example, using a single sign-on (SSO) authentication scheme or protocol. For example, the single sign-on (SSO) authentication scheme or protocol may authenticate the user 102 or the user's 102's digital identity via an identity provider (IdP). As shown in FIG. 2 , the computer system 110 receives the request and forwards the authentication request to an identity provider (IdP) 212, for example, hosted by the computer system 210. The identity provider (IdP) 212 may be configured to store and manage the digital identities of one or more users 102. The identity provider (IdP) 212 may verify the identity of the user 102 via an authenticator, for example, via a username and password combination or other factors, including biometric factors. Additionally, an ID provider (IdP) can authenticate any entity connected to a network or system, such as computer system 110, 140. In particular, ID provider (IdP) 212 can be used to manage user identities in a cloud computing environment. According to one embodiment, when user 102 or user 102 and computer system 110 are authenticated by ID provider (IdP) 212, computer system 110 associated with ID provider (IdP) 212 can send an authentication token (which may include, for example, a user ID and an authentication cookie) to user 102 and / or user 102 and computer system 110. Additionally, once user 102 is authenticated, the authenticator can store, for example, a biometric identifier or biometric sequence in cache lists 150, 152 for the next time user 102 wants to access computer system 110 for enhanced authentication, according to an exemplary embodiment.

[0025] According to one embodiment, the user 102 may, for example, identify one or more of the one or more computer systems 110 as favorites via a mobile application. One or more of the one or more computer systems 110 listed as the user's 102's favorites may, for example, pre-calculate a biometric sequence for the user 102 to help improve the user's 102 authentication time. Thus, when the user 102 contacts one or more computer systems 110, the user's 102's mobile device 140 may transmit a biometric identifier that can authenticate the user 102 to the one or more computer systems 110 via cache lists 150, 152. For example, the cache lists 150, 152 may include a biometric sequence that matches or authenticates the user 102 based on the received biometric identifier from the user's 102's mobile device 140.

[0026] According to another embodiment, users 102 can be added to one or more computer systems 110, e.g., one or more MFPs 112, using an administrative tool, for example, by adding a group of employees (i.e., multiple users 102) who work on the same floor, lab, or work bay, and cache lists 150, 152 can be generated for employees who regularly use or require access (e.g., for daily use) to one or more MFPs 112. Thus, by creating cache lists 150, 152 via the administrative tool, users 102 can be pre-cached, for example, at the MFP client of the MFP 112, which helps reduce the time required to authenticate one or more of the multiple users 102.

[0027] According to further embodiments, users 102 may designate one or more favorite computer systems 110, such as MFPs 112, via a remote application on mobile device 140 or other computer system. For example, prior to visiting an office or location, MFP 112 may be pre-configured with one or more users 102 who intend to use MFP 112 along with a biometric authentication device or sequence for each of the users 102.

[0028] 3 is a diagram of an infrastructure 300 for authenticating a user 102 on an MFP 112 according to an example embodiment. As shown in FIG. 3, the infrastructure 300 may include the MFP 112, an MFP client 114 hosted on the MFP 112, an authentication server 310, and a database 320 of users 102. The MFP client 114 may store a list of authenticated or authorized users 102 in encrypted form as a cache list 150 of users 102 authenticated or authorized to access the MFP 112. According to one embodiment, the cache list 150 may be a hardware or software component of the MFP 112.

[0029] According to one embodiment, user 102 can present an authenticator, e.g., a biometric identifier, to MFP 112, e.g., via mobile device 140. MFP 112 receives the biometric identifier and compares it to those biometric identifiers stored in cache list 150. If user 102's biometric identifier is stored in cache list 150, MFP client 114 of MFP 112 authenticates user 102 and issues an authentication token (e.g., which may include a user ID and an authentication cookie) that user 102 and MFP 112 can use to retrieve resources, e.g., managed print services 124, 134, from one or more computer systems 120, 130.

[0030] Alternatively, according to an alternative embodiment, if the biometric identifier of the user 102 received by the computer system 110 (e.g., the MFP 112) is not included in the cache list 150 of the MFP 112, the MFP client 114 can forward the biometric identifier of the user 102 to an authentication provider 130 (e.g., an identity provider (IdP)) that can authenticate the biometric identifier of the user 102 via a database 320. If the biometric identifier of the user 102 is included in the database 320, the authentication server 310 can send an authentication token (which may include, for example, a user ID and an authentication cookie) to the MFP 112 for the user 102 to access the managed print services 124, 134 hosted on the computer systems 120, 130.

[0031] As shown in FIG. 3, infrastructure 300 may include authentication server 310 and corresponding database 320 of authorized users 102. For example, authentication server 310 and corresponding database 320 may be identity provider (IdP) 212 (FIG. 2) configured to store and manage digital identities of one or more users 102. Identity provider (IdP) 212 may check an authentication token for user 102, and if the authentication token is valid, the identity provider may authorize user 102 to access one or more relying party applications or managed print services hosted on computer system 110, such as MFP 112, or one or more computer systems 120, 130 (FIG. 1) that may be associated with identity provider 320. According to one embodiment, one or more relying party applications may be, for example, a managed print service (MPS) for multifunction peripheral or multifunction printer (MFP) 112.

[0032] According to one embodiment, an authentication service 320 (i.e., an identity provider (IdP) 212) may be used in a cloud computing environment to manage user identities. According to one embodiment, when a user 102, or a user 102 and a computer system 110, is authenticated by an identity provider (IdP) 212, a computer system 120 associated with the authentication service 310 (e.g., the identity provider (IdP)) may send an authentication token (which may include, for example, a user ID and an authentication cookie).

[0033] FIG. 4 is a diagram of a flow 400 for authenticating a user 102 in an exemplary embodiment. As shown in FIG. 4 , the user 102 may have a client device 140, for example, in the form of a smart device that hosts a mobile authentication application 142. According to one embodiment, the user 102 may log in to the mobile authentication application 142, for example, by entering the user's 102 biometric identifier, such as a fingerprint or facial recognition. According to one embodiment, the biometric identifier may be, for example, the same biometric identifier that the user 102 uses to unlock the client device 140. Once the user 102 logs in to the mobile application 142, the user 102 may be presented with a list of MFPs 144, and the user 102 may select one or more of the MFPs 112 as favorites for pre-authentication. The identity of the MFPs 144 selected by the user 102 may be transmitted from the client device 140 to the server 130, which processes the authentication request.

[0034] According to one embodiment, for example, a multifunction peripheral or multifunction printer (MFP) 112 and / or a managed print service (MPS) may have an acceptance policy for registered client devices 140 that requires a particular authenticator, such as at least one biometric identifier, two-factor authentication (2FA), or multi-factor authentication, to be verified by server 130. According to one embodiment, server 130 may create a database 340 of users 102 that identifies one or more MFPs 112 as favorites for each of one or more users 102. An MFP client of MFP 112 receives a list of the user's favorites and corresponding authentication information, such as a biometric identifier or biometric sequence, which is then stored in a cache list 150 on MFP 112. For example, cache list 150 may be an encrypted cache list 150.

[0035] According to one embodiment, user 102 can access MFP 112, for example, by opening a mobile application on client device 140, which presents user 102 with a login or sign-in screen and requires user 102 to enter a password or biometric to unlock an authenticator in client device 140. Client device 140 uses the user's account identifier provided by MFP 112 to select the correct authentication method. Client device 140 sends the authenticator back to MFP 112, which verifies the authenticator and logs user 102 in (or signs in) to MFP 112.

[0036] According to one embodiment, the MFP 112 may be configured to send a request for an authenticator to the client device 140 when the client device 140 is brought within a certain distance of the MFP 112. For example, communication between the client device 140 and the MFP 112 may occur via near-field communication or Bluetooth protocols, and may occur via detection of the client device 140 or tapping the MFP 112 on a reader on the MFP 112. Thus, the user 102 may be authorized to access the MFP 112 without opening an application on the client device 140. Once the user 102 is authenticated on the MFP 112, the user 102 may access, for example, managed print services 124, 134 to which the user 102 has been authorized, for example, by an administrator.

[0037] According to embodiments, methods and systems for enhanced authentication as disclosed herein may also be integrated with one or more federation protocols, such as Security Assertion Markup Language (SAML), OpenID Connect (OIDC), and Open Authorization (OAuth2). Additionally, methods and systems as disclosed herein may be utilized in an OAuth2 environment for user authentication prior to user consent and authorization to access protected resources, such as managed print services.

[0038] Figure 5 is a flowchart 500 for a method for enhanced authentication of a user, according to one embodiment. As shown in Figure 5, the method for enhanced authentication includes, in step 510, receiving authentication information from a client device on a computer system. In step 520, the authentication information received from the client device is compared to authentication information in a list of authorized users hosted in a cache on the computer system. In step 530, if the authentication information received from the client device matches authentication information associated with a user in the list of authorized users in the cache of the computer system, the user is authenticated for access to the computer system.

[0039] According to one embodiment, the method further includes, upon authentication of a user in a list of authorized users cached in the computer system, granting the user an authentication token configured to provide the user access to one or more relying party applications. For example, the computer system may be one or more multifunction peripherals or multifunction printers, the client device may be a mobile device, and the method may include using the authentication token to access a managed print service on the one or more relying party applications.

[0040] According to one embodiment, the method further includes encrypting the list of authorized users in the computer system's cache. The method may include forwarding, by the computer system, the authentication information received from the client device to an authentication server if the authentication information is not associated with a user in the list of authorized users in the computer system's cache. The method may further include receiving, by the computer system, an authentication token for the user from the authentication server when the authentication server authenticates the authentication information. The method may also include storing the user's authentication information in the list of authorized users in the computer system's cache upon receiving the authentication token for the user from the authentication server. According to one embodiment, the authentication server may be an identity service provider.

[0041] According to one embodiment, the computer system is one or more multifunction peripherals or multifunction printers and the client device is a mobile device, and the method further includes detecting the user's mobile device by the one or more multifunction peripherals or multifunction printers via contactless or touch of the mobile device and the one or more multifunction peripherals or multifunction printers.

[0042] According to one embodiment, the method may include updating the list of authorized users in a cache of the computer system at predetermined time intervals, which may be, for example, one second or greater, such as every 5 seconds, 10 seconds, 20 seconds, 30 seconds, 45 seconds, 1 minute, 5 minutes, 10 minutes, 30 minutes, or 60 minutes.

[0043] According to one embodiment, the method further includes receiving, by the computer system from an external server, a list of authorized users to be stored in a cache of the computer system, the list of authorized users including an authentication sequence for the user to be stored in the cache of the computer system. The authentication sequence can be based on a biometric identifier for the user, the biometric identifier from a biometric authentication device associated with the client device, the biometric device including one or more of a sensor, a scanning device, or an electronic reader, and the biometric identifier of the user is at least one physiological characteristic of the user, the at least one physiological characteristic being selected from one or more of a fingerprint, palm vein, facial recognition, DNA (deoxyribonucleic acid), palm print, hand geometry, iris recognition, retina, and / or odor / fragrance.

[0044] According to one embodiment, the method further includes generating a list of authorized users for each authenticated user on the computer system, and may include removing the user from the list of authorized users after a predetermined period of time if the user has not accessed the computer system within the predetermined period of time.

[0045] According to one embodiment, the client device is a mobile device, a smartphone, or a wearable device, and the computer system is a multifunction peripheral or a multifunction printer, wherein the method further includes communicating with the computer system via a wireless communication protocol, the wireless communication protocol being a near field communication (NFC) or Bluetooth technology standard, and granting the user access to one or more managed print service providers by the service provider for the multifunction peripheral or the multifunction printer.

[0046] According to one embodiment, the authentication information from the client device to the computer system is the same authentication information used by the user to access the client device, and the same authentication information is at least one of a biometric identifier or multi-factor authentication.

[0047] According to one embodiment, the computer system is a multifunction peripheral or a multifunction printer, and the method further includes granting the user access to a managed print service hosted by a service provider external to the multifunction peripheral or multifunction printer.

[0048] 6 illustrates a representative computer system 600, in which embodiments of the present disclosure, or portions thereof, can be implemented as computer-readable code executing on hardware. For example, one or more computer systems 110, 112, 120, 130, 310, 320, or client device 140 associated with the enhanced authentication methods and systems disclosed herein may be implemented in whole or in part by computer system 600, or may be implemented in one or more computer systems or other processing systems, using hardware, software executing on hardware, firmware, non-transitory computer-readable media having instructions stored thereon, or a combination thereof. The hardware, software executing on hardware, or a combination thereof, may embody the modules and components used to implement the methods and steps of the presently described methods and systems.

[0049] Where programmable logic is used, such logic is executed on a commercially available processing platform configured by executable software code, which may be a special-purpose computer or a special-purpose device (e.g., a programmable logic array, an application-specific integrated circuit, etc.). Those skilled in the art will appreciate that embodiments of the disclosed subject matter can be practiced in a variety of computer system configurations, including multi-core multiprocessor systems, minicomputers, mainframe computers, computers linked or clustered with distributed functionality, and pervasive or miniature computers that may be embedded in virtually any device. For example, the foregoing embodiments may be implemented using at least one processor device and one memory.

[0050] A processor unit or device as described herein may be a single processor, multiple processors, or a combination thereof. A processor device may have one or more processor “cores.” As used herein, the terms “computer program medium,” “non-transitory computer-readable medium,” and “computer-usable medium” are generally used to refer to tangible media, such as removable storage device 618, removable storage device 622, or a hard disk installed in hard disk drive 612.

[0051] Various embodiments of the present disclosure are described with reference to this exemplary computer system 600. After reading this specification, it will be apparent to one skilled in the relevant art how to implement the present disclosure using other computer systems and / or computer architectures. While operations are described as sequential processes, in reality, some operations are performed in parallel, concurrent, and / or distributed environments, with program code stored locally or remotely for access from single-processor or multi-processor machines. Also, in some embodiments, the order of operations may be rearranged without departing from the spirit of the disclosed subject matter.

[0052] The processor device 604 may be a processor device specially configured to perform the functions described herein. The processor device 604 may be connected to a communications infrastructure 606, such as a bus, message queue, network, or multi-core message passing scheme. The network may be any network suitable for performing the functions disclosed herein and may include a local area network ("LAN"), a wide area network ("WAN"), a wireless network ("wi-fi"), a mobile communications network, a satellite network, the Internet, fiber optics, coaxial cable, infrared, radio frequency ("RF"), or combinations thereof. Other suitable network types and configurations will be apparent to those skilled in the relevant art. The computer system 600 may include a main memory 608 (e.g., random access memory, read-only memory, etc.) and may also include a secondary memory 610. The secondary memory 610 may include a hard disk drive 612 and a removable storage drive 614, such as a floppy disk drive, magnetic tape drive, optical disk drive, or flash memory.

[0053] Removable storage drive 614 can read from and / or write to removable storage device 618 in a well-known manner. Removable storage device 618 may include a removable storage medium that is read from and written to by removable storage drive 614. For example, if removable storage drive 614 is a floppy disk drive or a Universal Serial Bus port, removable storage device 618 may be a floppy disk or a portable flash drive, respectively. In one embodiment, removable storage device 618 may be a non-transitory computer-readable recording medium.

[0054] In some embodiments, secondary memory 610 may include alternative means for allowing computer programs and other instructions to be loaded into computer system 600, such as, for example, removable storage device 622 and interface 620. Examples of such means may include program cartridges and cartridge interfaces (e.g., those found in video game systems), removable memory chips (e.g., EEPROM, PROM, etc.) and associated sockets, and other removable storage devices 622 and interfaces 620 as would be apparent to one skilled in the relevant art.

[0055] Data stored in computer system 600 (e.g., stored in main memory 608 and / or secondary memory 610) may be stored on a suitable computer-readable medium, such as an optical storage device (e.g., a compact disc, digital versatile disc, or Blu-ray disc) or a magnetic storage device (e.g., a hard disk drive). The data may be organized in any type of suitable database configuration, such as a relational database, a structured query language (SQL) database, a distributed database, or an object database. Suitable configurations and storage types will be apparent to those skilled in the relevant art.

[0056] Computer system 600 may also include a communications interface 624. Communications interface 624 may be configured to allow software and data to be transferred between computer system 600 and external devices. Exemplary communications interface 624 may include a modem, a network interface (e.g., an Ethernet card), a communications port, a PCMCIA slot and card, etc. The software and data transferred via communications interface 624 may be in the form of signals, which may be electronic, electromagnetic, optical, or other signals apparent to those skilled in the relevant art. The signals may be transmitted over communications path 626, which is configured to transmit signals and which may be implemented using wire, cable, fiber optics, a telephone line, a cellular phone link, a radio frequency link, etc.

[0057] The computer system 600 may further include a display interface 602. The display interface 602 may be configured to allow data to be transferred between the computer system 600 and an external display 630. Exemplary display interfaces 602 may include a high-definition multimedia interface (HDMI), a digital visual interface (DVI), a video graphics array (VGA), etc. The display 630 may be any type of display suitable for displaying data transmitted via the display interface 602 of the computer system 600, such as a cathode ray tube (CRT) display, a liquid crystal display (LCD), a light-emitting diode (LED) display, a capacitive touch display, a thin-film transistor (TFT) display, etc. Computer program media and computer-usable media may refer to memory, such as the main memory 608 and the secondary memory 610, which may be memory semiconductors (e.g., DRAM). These computer program products may be means for providing software to the computer system 600. Computer programs (e.g., computer control logic) may be stored in the main memory 608 and / or the secondary memory 610. Computer programs may also be received via the communication interface 624. Such computer programs, when executed, may enable computer system 600 to perform the present methods as described herein. In particular, when executed, the computer programs may enable processor device 604 to perform the methods described herein and shown in Figures 1 through 5. Such computer programs may therefore represent controllers of computer system 600. When the present disclosure is implemented using software executed on hardware, the software is stored in a computer program product and loaded into computer system 600 using removable storage drive 614, interface 620, and hard disk drive 612, or communication interface 624.

[0058] The processor device 604 may be comprised of one or more modules or engines configured to perform the functions of the computer system 600. Each module or engine may be implemented using hardware and, in some cases, may utilize software executing on the hardware, such as corresponding to program code and / or programs stored in the main memory 608 or the secondary memory 610. In such cases, the program code may be compiled by the processor device 604 (e.g., by a compilation module or engine) before being executed by the hardware of the computer system 600. For example, the program code may be source code written in a programming language that has been translated into a lower-level language, such as assembly language or machine code, for execution by the processor device 604 and / or additional hardware components of the computer system 600. The compilation process may include the use of lexical analysis, preprocessing, syntactic analysis, semantic analysis, syntax-directed translation, code generation, code optimization, and other techniques suitable for translating program code into a low-level language suitable for controlling the computer system 600 to perform the functions disclosed herein. It will be apparent to those skilled in the relevant art that the computer system 600 may be a computer system 600 specially programmed to perform the functions described above.

[0059] According to an exemplary embodiment, the disclosed methods and processes can be implemented on a non-transitory computer-readable medium. The non-transitory computer-readable medium may be a magnetic recording medium, a magneto-optical recording medium, or any other recording medium developed in the future, all of which are considered equally applicable to the present invention. Copies of such media, including primary and secondary duplicate products, are undoubtedly considered equivalent to the above-mentioned media. Furthermore, even if an embodiment of the present invention is a combination of software and hardware, it does not depart from the spirit of the invention. The present disclosure may be implemented such that the software portion thereof is pre-written on a recording medium and read as needed during operation.

[0060] As used herein, elements or steps referred to in the singular and preceded by the words "a" or "an" should be understood as not excluding a plurality of elements or steps unless such exclusion is expressly stated. Furthermore, references to "an example embodiment" or "one embodiment" of the present disclosure are not intended to be interpreted as excluding the existence of additional examples that also incorporate the recited features.

[0061] The patent claims at the end of this document are not intended to be construed under 35 U.S.C. Sec. 112(f) unless traditional means-plus-function language is expressly recited.

[0062] It will be apparent to those skilled in the art that various modifications and variations can be made to the structure of the present invention without departing from the scope or spirit of the invention. In view of the foregoing, it is intended that the present invention cover modifications and variations of this invention provided they come within the scope of the following claims and their equivalents.

Claims

1. receiving authentication information from a client device on a computer system; comparing the authentication information received from the client device with authentication information in a list of authorized users hosted in a cache on the computer system; authenticating the user for access to the computer system if the authentication information received from the client device matches authentication information associated with a user in the list of authorized users in the cache of the computer system; Equipped with forwarding, by the computer system, the authentication information received from the client device to an authentication server if the authentication information is not associated with the user in the list of authorized users in the cache of the computer system; receiving, by the computer system, an authentication token for the user from the authentication server when the authentication server authenticates the authentication information; 10. The method of enhanced authentication, further comprising, upon receiving the authentication token for the user from the authentication server, storing the authentication information of the user in the list of authorized users in the cache of the computer system.

2. receiving authentication information from a client device on a computer system; comparing the authentication information received from the client device with authentication information in a list of authorized users hosted in a cache on the computer system; authenticating the user for access to the computer system if the authentication information received from the client device matches authentication information associated with a user in the list of authorized users in the cache of the computer system; Equipped with The method of enhanced authentication further comprises receiving by the computer system from an external server the list of authorized users to be stored in the cache of the computer system, the list of authorized users including authentication sequences for the users to be stored in the cache of the computer system.

3. receiving authentication information from a client device on a computer system; comparing the authentication information received from the client device with authentication information in a list of authorized users hosted in a cache on the computer system; authenticating the user for access to the computer system if the authentication information received from the client device matches authentication information associated with a user in the list of authorized users in the cache of the computer system; Equipped with 1. A method of enhanced authentication, wherein the authentication information from the client device to the computer system is the same authentication information used by the user to access the client device, and the same authentication information is at least one of a biometric identifier or multi-factor authentication.

4. 4. The method of claim 1, further comprising, upon authentication of the user of the list of authorized users in the cache of the computer system, granting the user an authentication token, the authentication token configured to provide the user with access to one or more relying party applications.

5. the computer system is one or more multifunction peripherals or multifunction printers, the client device is a mobile device, and The method of claim 4 , wherein the method comprises using the authentication token to access a managed print service on the one or more relying party applications.

6. The method of claim 1 , further comprising encrypting the list of authorized users in the cache of the computer system.

7. The method of claim 1 , wherein the authentication server is an identity service provider.

8. the computer system is one or more multifunction peripherals or multifunction printers, the client device is a mobile device, and 4. The method of claim 1, wherein the method comprises detecting the mobile device of the user by the one or more multifunction peripherals or multifunction printers via contactless or touch of the mobile device and the one or more multifunction peripherals or multifunction printers.

9. 4. The method of claim 1, further comprising updating the list of authorized users in the cache of the computer system at predetermined time intervals.

10. 3. The method of claim 2, wherein the authentication sequence is based on a biometric identifier of the user, the biometric identifier being provided from a biometric device associated with the client device, the biometric device including one or more of a sensor, a scanning device, or an electronic reader, and the biometric identifier of the user is at least one physiological characteristic of the user, the at least one physiological characteristic being selected from one or more of a fingerprint, palm vein, facial recognition, DNA (deoxyribonucleic acid), palm print, hand geometry, iris recognition, retina, and / or odor / fragrance.

11. The method of claim 1 , further comprising generating the list of authorized users for each of the users authenticated on the computer system.

12. 12. The method of claim 11, further comprising removing the user from the list of authorized users after a predetermined period of time if the user has not accessed the computer system within the period of time.

13. The client device is a mobile device, a smartphone, or a wearable device, and the computer system is a multifunction peripheral or a multifunction printer, and the method includes: communicating with said computer system via a wireless communication protocol, such as Near Field Communication (NFC) or Bluetooth technology standards; The method of claim 1 , further comprising granting the user access to one or more managed print service providers by a service provider for the multifunction peripheral or the multifunction printer.

14. 4. The method of claim 1, wherein the computer system is a multifunction peripheral or a multifunction printer, and the method further comprises granting the user access to a managed print service hosted by a service provider external to the multifunction peripheral or multifunction printer.

15. 1. A computer program for accessing a multifunction peripheral device, comprising: and program instructions executable by a computer, the program instructions causing the computer to: receiving authentication information from a client device on the computer; comparing the authentication information received from the client device with authentication information in a list of authorized users hosted in a cache on the computer; and authenticating the user for access to the computer if the authentication information received from the client device matches authentication information associated with a user in the list of authorized users in the cache of the computer; forwarding, by the computer, the authentication information received from the client device to an authentication server if the authentication information is not associated with the user in the list of authorized users in the cache of the computer; receiving, by the computer, an authentication token for the user from the authentication server when the authentication server authenticates the authentication information; 1. The computer program product of claim 1, further comprising: upon receiving the authentication token for the user from the authentication server, storing the authentication information of the user in the list of authorized users in the cache of the computer.

16. 1. A computer program for accessing a multifunction peripheral device, comprising: and program instructions executable by a computer, the program instructions causing the computer to: receiving authentication information from a client device on the computer; comparing the authentication information received from the client device with authentication information in a list of authorized users hosted in a cache on the computer; and authenticating the user for access to the computer if the authentication information received from the client device matches authentication information associated with a user in the list of authorized users in the cache of the computer; 1. A computer program product for executing a process, further comprising receiving, by the computer from an external server, the list of authorized users to be stored in the cache of the computer, wherein the list of authorized users includes authentication sequences for the users to be stored in the cache of the computer.

17. 1. A computer program for accessing a multifunction peripheral device, comprising: and program instructions executable by a computer, the program instructions causing the computer to: receiving authentication information from a client device on the computer; comparing the authentication information received from the client device with authentication information in a list of authorized users hosted in a cache on the computer; and authenticating the user for access to the computer if the authentication information received from the client device matches authentication information associated with a user in the list of authorized users in the cache of the computer; 1. A computer program product that executes a process in which the authentication information from the client device to the computer is the same authentication information used by the user to access the client device, the same authentication information being at least one of a biometric identifier or multi-factor authentication.

18. 18. The computer program product of claim 15, further comprising, upon authentication of the user of the list of authorized users of the cache of the computer, granting the user an authentication token, the authentication token configured to provide the user with access to one or more relying party applications.

19. the computer is one or more multifunction peripherals or multifunction printers; the client device is a mobile device; 20. The computer program product of claim 18, wherein the process comprises using the authentication token to access a managed print service on the one or more relying party applications.

20. Cache and a multifunction peripheral device comprising: the processor: Receives authentication information from the client device, comparing authentication information received from the client device with authentication information in a list of authorized users hosted in the cache of the multifunction peripheral; if the authentication information received from the client device matches the authentication information associated with a user in the list of authorized users in the cache of the multifunction peripheral, authenticating the user for access to the multifunction peripheral; forwarding, by the multifunction peripheral device, the authentication information received from the client device to an authentication server if the authentication information is not associated with the user in the list of authorized users in the cache of the multifunction peripheral device; receiving, by the multifunction peripheral device, an authentication token for the user from the authentication server when the authentication server authenticates the authentication information; a multifunction peripheral configured to, upon receiving the authentication token for the user from the authentication server, store the authentication information of the user in the list of authorized users in the cache of the multifunction peripheral.

21. Cache and a multifunction peripheral device comprising: the processor: Receives authentication information from the client device, comparing authentication information received from the client device with authentication information in a list of authorized users hosted in the cache of the multifunction peripheral; if the authentication information received from the client device matches the authentication information associated with a user in the list of authorized users in the cache of the multifunction peripheral, authenticating the user for access to the multifunction peripheral; A multifunction peripheral device further comprising receiving by the multifunction peripheral device from an external server the list of authorized users to be stored in the cache of the multifunction peripheral device, wherein the list of authorized users is configured to include authentication sequences for the users to be stored in the cache of the multifunction peripheral device.

22. Cache and a multifunction peripheral device comprising: the processor: Receives authentication information from the client device, comparing authentication information received from the client device with authentication information in a list of authorized users hosted in the cache of the multifunction peripheral; if the authentication information received from the client device matches the authentication information associated with a user in the list of authorized users in the cache of the multifunction peripheral, authenticating the user for access to the multifunction peripheral; A multifunction peripheral configured such that the authentication information from the client device to the multifunction peripheral is the same authentication information used by the user to access the client device, the same authentication information being at least one of a biometric identifier or multi-factor authentication.

Citation Information

Patent Citations

  • Information processing device, information processing method, program, and information processing system

    JP2015176194A

  • Information processing system, image processing device, information processing method, and information processing program

    JP2016123090A

  • Image processing apparatus, method, program, and system

    JP2018198400A

  • Information processing device, method in information processing device, and program

    JP2019096077A

  • Secure single sign on and conditional access for client applications

    JP2020166906A