Authentication Apparatus for Multi-Factor Network Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional image forming apparatus management systems face challenges in user authentication when transitioning between private and public networks, such as cloud services, as they require separate authentication data, which is inconvenient for users and poses security risks if the same data is used across both networks.

Innovation Solution

A method and system that perform user authentication by storing first authentication data used for private network access in association with second authentication data for public network access, allowing seamless coordination between private and public network authentications while maintaining security through a storage unit connected to both networks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If separate authentication data is used for private network and public network, then information security is improved, but user convenience deteriorates

Engineering Contradiction:
Improveinformation securityVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The authentication system is segmented into two distinct authentication data sets: first authentication data for private network access and second authentication data for public network access. This segmentation allows each network type to have its own dedicated credentials, maintaining security isolation while enabling the system to manage different authentication requirements separately.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The authentication apparatus is designed with multi-functionality to handle both private network authentication and public network authentication. It can store and process multiple types of authentication data (first and second authentication data) and coordinate between them, making the system universally applicable to different network environments without requiring separate systems.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Ease of operation

If the same authentication data is used for both private network and public network, then user convenience is improved, but information security deteriorates

Engineering Contradiction:
Improveuser convenienceVSAvoidinformation security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The authentication apparatus acts as an intermediary between the terminal and the networks. It stores associations between first authentication data (private network) and second authentication data (public network), and coordinates the authentication process. This intermediary role allows the system to maintain separate security domains while providing seamless user experience through automatic credential management.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If separate authentication data is required for each network, then information security is improved, but authentication process complexity increases

Engineering Contradiction:
Improveinformation securityVSAvoidauthentication process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication apparatus combines multiple authentication data sets (first and second authentication data) into a single storage unit, and merges the authentication processes by coordinating them through a unified apparatus. This merging reduces the overall system complexity by consolidating what would otherwise require separate authentication systems into one integrated solution.

Inventive Principle:
Principle #5Merging (Combining)

4Reliability

If users must input authentication data for each function/service, then information security is improved, but ease of operation deteriorates

Engineering Contradiction:
Improveinformation securityVSAvoidease of operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The authentication apparatus performs preliminary actions by pre-storing the associations between first authentication data and second authentication data. When authentication is required, the system has already prepared the credential mappings, eliminating the need for users to manually input authentication data for each service. This preliminary setup maintains security while greatly improving ease of operation.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9203822B2Network system, data processing apparatus, and method for multi-factor authentication
Publication Date: 2015.12.01 RICOH CO LTD
  • US9203822B2 patent drawing
  • US9203822B2 patent drawing
  • US9203822B2 patent drawing

AI summary

A method for processing data with a terminal and a system connected to the terminal via a network, which includes the steps of executing a process according to a request transmitted from the terminal via the network, performing a first user authentication with respect to the terminal by using the terminal or an authentication apparatus connected to the terminal via the network, storing first authentication data used for the first user authentication in association with second authentication data used for a second user authentication in a storage unit, and performing the second user authentication with respect to the system. In a case where at least a portion of the first authentication data is authenticated by the first user authentication, the second user authentication is performed by using the first and second authentication data stored in the storage unit and the portion of the first authentication data.