Application-Specific Authentication Management for Multi-User Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In multi-user image formation devices, saved user authentication information can lead to unauthorized access to external services, as the web browser does not effectively manage user authentication for different users.

Innovation Solution

A communication system with an image generation server and an information processing apparatus that creates a second application with unique authentication information, allowing user authentication to be managed differently for each user, ensuring only authorized users access external services.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If the web browser saves user authentication information for external services, then user authentication can be passed using saved information, but unauthorized users may access external services in multi-user environments

Engineering Contradiction:
Improveauthentication convenienceVSAvoidaccess security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments authentication management by creating separate authentication information storage for each application. The authentication information management unit stores authentication information in association with specific application identification, so that each application has its own dedicated authentication credentials. This prevents cross-application authentication leakage while maintaining convenience for each application.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies local quality by making authentication information application-specific rather than globally shared. Each application receives authentication information tailored to its specific service and requirements, stored with its unique identification. This ensures that authentication credentials are appropriately scoped to each application's context, enhancing security while maintaining operational convenience.

Inventive Principle:
Principle #3Local quality

2Device complexity

If a single web browser manages authentication for all applications, then authentication management is simplified, but user-specific authentication control cannot be implemented

Engineering Contradiction:
Improveauthentication management complexityVSAvoiduser authentication management flexibility
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The patent segments authentication management into application-specific units. Each application has its own authentication information stored and managed separately by the authentication information management unit. This segmentation allows the system to maintain relatively simple overall architecture while providing flexible, user-specific authentication control for each application through the use of application identification and associated authentication credentials.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS20250007906A1Communication system and information processing apparatus
Publication Date: 2025.01.02 CANON KK
  • US20250007906A1 patent drawing
  • US20250007906A1 patent drawing
  • US20250007906A1 patent drawing

AI summary

A communication system includes an image generation server configured to performs rendering of web contents and an information processing apparatus configured to execute a first application to be managed with first management information and acquire the web contents related to a result of the rendering includes one or more controllers including one or more processors and one or more memories, the one or more controllers being configured to create a second application to be managed with second management information different from the first management information and acquire web contents based on the result of the rendering, and set authentication information to the second application.