Device Administrator Authentication Handover via Maintenance Inspector

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In an operation form using multi-factor authentication for device administrator authentication, sudden absence of the device administrator without person-in-charge handover leads to inability to manage the device, as shared first authentication information is insufficient without alternative second authentication information like biological data.

Innovation Solution

An information processing system with a processor that recognizes a new device administrator upon receipt of first and second authentication information, resets or overwrites the second authentication information upon instruction from a user in a predetermined authority group, and initializes the first authentication information when the second is reset or overwritten.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multi-factor authentication is used for device administrator authentication, then security is improved, but device management becomes unavailable when the device administrator is suddenly absent

Engineering Contradiction:
ImprovesecurityVSAvoiddevice management availability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces a maintenance inspector as an intermediary role who can perform administrator functions when the device administrator is absent. The maintenance inspector acts as a mediator between the locked-out administrator and the system, enabling continuous device management through this backup role with specific reset capabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system pre-configures a maintenance inspector role with specific authorities before the device administrator becomes unavailable. By establishing this backup role in advance with reset capabilities for authentication information, the system ensures management continuity without requiring real-time administrator presence.

Inventive Principle:
Principle #10Preliminary action

2Ease of operation

If maintenance inspector is given authority to reset authentication information, then device management continuity is improved, but security is worsened

Engineering Contradiction:
Improvedevice management continuityVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The maintenance inspector role is granted selective, localized authorities rather than full administrator privileges. Specifically, the maintenance inspector can only reset authentication information for other users except the device administrator themselves, creating a controlled, limited scope of power that balances continuity needs with security constraints.

Inventive Principle:
Principle #3Local quality

3Reliability

If device initialization is required to restore original state, then security is improved, but device complexity is worsened

Engineering Contradiction:
ImprovesecurityVSAvoidrestoration process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the authentication information reset function from the full device initialization process. By allowing the maintenance inspector to selectively reset only authentication information through a targeted operation, the system separates this specific restoration need from the comprehensive device initialization, reducing complexity while maintaining security through controlled access.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS20250028811A1Information processing system and non-transitory computer readable medium
Publication Date: 2025.01.23 FUJIFILM BUSINESS INNOVATION CORP
  • US20250028811A1 patent drawing
  • US20250028811A1 patent drawing
  • US20250028811A1 patent drawing

AI summary

An information processing system includes a processor configured to recognize a new device administrator as a device administrator in a case where first authentication information and second authentication information for the device administrator are received, reset or overwrite the second authentication information in a case where an instruction to reset or overwrite the second authentication information is given by a user belonging to a predetermined authority group permitted to reset or overwrite the second authentication information for the device administrator, and perform processing of initializing the first authentication information for the device administrator in a case where the second authentication information is reset or overwritten.