Authentication Unit for Guest Network Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing techniques for connecting guest users to an intra-organization LAN lack flexibility in permission control, requiring host users to perform cumbersome operations to manage access for multiple guests, compromising security and ease of use.

Innovation Solution

A communication system comprising a first communication unit, an authentication unit, a connection guiding unit, a display unit, and an input unit, which facilitates secure and easy connection of guest devices by transmitting authentication screens, displaying input information, and controlling connections based on user input, allowing host users to manage access without changing access point settings.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If host users perform operations to change settings on an access point to control permission for connection, then permission control can be achieved, but the operation becomes very troublesome when there are a large number of guest users

Engineering Contradiction:
Improveease of permission controlVSAvoidtime for managing guest connections
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The patent introduces an authentication unit as an intermediary between the access point and guest terminals. This authentication unit handles all authentication requests and permission control operations, freeing host users from the burden of manually changing access point settings. The authentication unit receives authentication information from terminals, determines whether to permit connection, and notifies the access point accordingly, thus resolving the contradiction by providing automated permission control.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system enables self-service authentication where terminals automatically perform authentication by inputting authentication information and receiving authentication screens from the authentication unit. Host users only need to provide initial authentication information to guest users, after which the authentication unit autonomously handles all subsequent connection permissions without requiring host user intervention, significantly reducing time loss for managing multiple guests.

Inventive Principle:
Principle #25Self-service

2Ease of operation

If guest users can easily be connected to the LAN, then ease of use is improved, but security control over individual guest access is compromised

Engineering Contradiction:
Improveease of connectionVSAvoidsecurity control
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the connection control function into two independent parts: the authentication unit that handles security verification and permission determination, and the access point that provides network access. This segmentation allows the access point to easily connect guests while the authentication unit independently performs security control by verifying authentication information and selectively permitting connections based on authentication results, thus resolving the contradiction between ease of connection and security control.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The authentication unit acts as a security intermediary between guest terminals and the internal network. It receives authentication information from terminals, performs security verification, determines connection permissions, and notifies the access point accordingly. This intermediary mechanism enables easy connection for authenticated guests while maintaining strict security control over individual guest access without requiring host users to manually configure access point settings for each guest.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP3289514B1Communication system, communication method, and computer program
Publication Date: 2024.02.28 RICOH CO LTD
  • EP3289514B1 patent drawingFigure 1~2
  • EP3289514B1 patent drawingFigure 3~4
  • EP3289514B1 patent drawingFigure 5~6

AI summary

A communication system includes: a first communication unit configured to communicate with a terminal apparatus; an authentication unit configured to transmit an authentication screen for inputting authentication information, in response to access from the terminal apparatus; a connection guiding unit configured to connect communication made from the terminal apparatus via the first communication unit and addressed to any destination, to the authentication unit; a display unit configured to display the authentication information input to the authentication screen and output by the terminal apparatus that has been connected to the authentication unit by the connection guiding unit and to which the authentication screen has been transmitted; and a connection control unit configured to permit connection of the terminal apparatus to a network via a second communication unit in accordance with the user input received by the input unit according to display by the display unit.