Authentication Header Authority Segmentation for Background Apps

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Image forming apparatuses require users to log in multiple times and switch between user and administrator authorities for various operations, leading to inefficiencies and limitations in accessing necessary resources.

Innovation Solution

The apparatus separates operation and main units, allowing background application software to operate with either user or administrator authority without requiring concurrent user login, by using authentication headers in requests to determine and manage authority levels.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a user logs in to perform operations with administrator authority, then the user can access necessary resources and execute jobs, but the user must log in multiple times and switch between user and administrator authorities, leading to inefficiency and complexity

Engineering Contradiction:
Improvelogin processVSAvoidtime for multiple logins
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The patent segments the authentication process by introducing distinct authentication headers for user authority and administrator authority. The authentication header includes a flag indicating the authority type, allowing the system to differentiate between user and administrator authentication requests. This segmentation enables background application software to operate with appropriate authority levels without requiring the user to manually switch between logins, thereby reducing operational complexity and time loss.

Inventive Principle:
Principle #1Segmentation

2Productivity

If background application software operates with administrator authority without user login, then resource access and job execution are enabled, but security risks may increase

Engineering Contradiction:
Improvebackground operation capabilityVSAvoidsecurity
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent introduces an authentication header as an intermediary mechanism that carries authority information between the background application software and the information processing apparatus. The authentication header includes a flag indicating administrator authority, allowing the system to verify and enforce appropriate access rights without requiring direct user login. This intermediary ensures that background operations maintain security by validating authority through the authentication header while enabling productive background execution.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If the system requires concurrent user login for background application software to operate, then security is maintained, but the system becomes less flexible and more complex to operate

Engineering Contradiction:
Improveoperation flexibilityVSAvoidauthentication management
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements dynamic authentication management by allowing the authentication header to carry different authority flags depending on the operation context. The system dynamically adjusts the required authentication level based on whether the operation requires user or administrator authority. This dynamic approach enables background application software to operate with appropriate authority without requiring concurrent user login, thereby increasing operational flexibility while maintaining security through adaptive authentication requirements.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS11206255B2Information processing apparatus, authentication method, and non-transitory recording medium storing instructions for performing an information processing method
Publication Date: 2021.12.21 RICOH CO LTD
  • US11206255B2 patent drawing
  • US11206255B2 patent drawing
  • US11206255B2 patent drawing

AI summary

An improved information processing apparatus, an authentication method and non-transitory recording medium are provided. The information processing apparatus authenticates a user based on first authentication information input by a user to generate an authentication result based on the first authentication information, receives an authentication request generated by first application software, authenticates the first application software based on second authentication information to generate an authentication result based on the second authentication information when the authentication request includes the second authentication information, acquires the authentication result of the user based on the first authentication information when the authentication request does not include the second authentication information, and executes processing based on one of the authentication result based on the first authentication information and the authentication result based on the second authentication information.