Authentication Controller for Multi-Resource Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems require users to adhere to the strictest authentication conditions across multiple network resources, leading to decreased convenience as users must set authentication strengths according to the most stringent conditions, even for less frequently used resources.

Innovation Solution

An information processing apparatus with an authenticator, acquirer, and controller that allows users to access multiple network resources with a single authentication operation, where the system acquires and applies different authentication strength conditions for each resource, ensuring compliance only with the specific resource's policy.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the system requires compliance with the strictest authentication condition among multiple resources, then security reliability is improved, but user convenience deteriorates

Engineering Contradiction:
Improveauthentication securityVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system applies different authentication strength conditions to different resources based on their specific security requirements. The controller selects and applies the appropriate condition from multiple available conditions according to the target resource, rather than uniformly applying the strictest condition to all resources. This allows each resource to have its own localized authentication requirements matched to its actual security needs.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system changes the authentication parameters (strength conditions) dynamically based on the target resource. The acquirer obtains multiple different authentication strength conditions, and the controller selects the appropriate condition parameter set for each specific resource access request. This enables flexible adjustment of authentication requirements to match actual security needs of different resources.

Inventive Principle:
Principle #35Parameter changes

2Ease of operation

If a single authentication operation is used to access multiple resources, then ease of operation is improved, but authentication security may deteriorate

Engineering Contradiction:
Improveauthentication efficiencyVSAvoidauthentication security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system dynamically adjusts the authentication condition applied based on the target resource, even though the authentication operation itself is performed once. The controller receives the authentication result and then selectively applies the appropriate authentication strength condition corresponding to the specific resource being accessed. This dynamic selection ensures security is maintained at the resource level while preserving the efficiency of single authentication.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The controller acts as an intermediary between the single authentication operation and multiple resource accesses. It receives the authentication result and then mediates by selecting and applying the appropriate authentication condition for each specific resource based on pre-acquired condition sets. This intermediary function allows the system to maintain both authentication efficiency and security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11601416B2Information processing apparatus, information processing system, and non-transitory computer readable medium
Publication Date: 2023.03.07 FUJIFILM BUSINESS INNOVATION CORP
  • US11601416B2 patent drawing
  • US11601416B2 patent drawing
  • US11601416B2 patent drawing

AI summary

An information processing apparatus includes an authenticator that authenticates a user so that the user accesses plural resources on a network, an acquirer that acquires conditions that are related to a strength of authentication information and are provided differently for the respective resources, and a controller that controls, when the user accesses one resource out of the plural resources, access to the one resource based on a condition related to the strength for the one resource and strength information related to the strength of the authentication information of the user that is used by the authenticator.