Authentication Scheme Selector for Multi-Path User Login

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In network systems with multiple connected devices, managing user authentication across different devices and services is cumbersome, especially when third-party authentication schemes are involved, leading to inconvenience for users who cannot access services or applications unless authenticated by the system's own scheme.

Innovation Solution

A user authentication management device that receives login requests from various input paths and selects the appropriate authentication scheme corresponding to the path, allowing users to authenticate using different schemes without a complex procedure, enabling access to services and applications that require alternative authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a unified authentication server is used to manage user information across the system, then user information management becomes centralized and secure, but users cannot access third-party services that require different authentication schemes

Engineering Contradiction:
Improveuser information managementVSAvoidauthentication scheme compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The authentication server acts as an intermediary that receives authentication requests from multiple inputters through different paths. It mediates between the unified user information management system and various third-party authentication schemes by selecting appropriate authentication methods based on the request path, thereby enabling both centralized control and external compatibility.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The authentication server dynamically selects authentication schemes based on the input path of each login request. Instead of using a fixed authentication method, the server adapts its authentication approach according to the specific path and service requirements, enabling flexible support for both internal system authentication and third-party authentication schemes.

Inventive Principle:
Principle #15Dynamics

2Ease of operation

If multiple authentication schemes are supported for different services, then user convenience and service accessibility improve, but the authentication management system becomes complex

Engineering Contradiction:
Improveuser authentication convenienceVSAvoidauthentication management system
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The authentication management system is segmented into distinct authentication paths, each corresponding to different inputters and services. By dividing the authentication process into path-specific segments, the system can handle multiple authentication schemes independently through the same server infrastructure, reducing overall complexity while maintaining versatility.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The authentication server is designed with multi-functionality to handle various authentication schemes through a single unified platform. It can process authentication requests from multiple inputters using different authentication methods (internal authentication, third-party authentication, etc.) without requiring separate systems, thereby simplifying the overall architecture while supporting diverse authentication needs.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If the authentication server only accepts registered user IDs and passwords, then system security is maintained, but users authenticated by third parties cannot access system services

Engineering Contradiction:
Improvesystem securityVSAvoidservice accessibility
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The authentication server dynamically adjusts its acceptance criteria based on the authentication path. For requests through internal paths, it strictly validates against registered user IDs and passwords. For requests through third-party paths, it accepts authentication results from external services, thereby maintaining security for core operations while enabling access to integrated third-party services.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The server changes its authentication validation parameters according to the input path. It switches between strict internal validation (for system security) and flexible external validation (for third-party service integration), allowing the same server to enforce different security levels appropriate to each authentication context without compromising overall system security.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11588817B2User authentication management device, image processing apparatus including the same, user authentication management method, and storage medium
Publication Date: 2023.02.21 SHARP KK
  • US11588817B2 patent drawing
  • US11588817B2 patent drawing
  • US11588817B2 patent drawing

AI summary

Provided is a user authentication management device including a login request receiver that receives a login request from a user from a plurality of inputters via a path corresponding to each of the plurality of inputters, an authentication scheme selector that selects any one of a plurality of authentication schemes and provides identification information of a user related to the received login request to the selected authentication scheme to perform user authentication, and a user information storage that stores a user authentication result received from the selected authentication scheme as user information related to the user, in which the authentication scheme selector selects an authentication scheme predetermined corresponding to a path through which the login request is received.