Authentication apparatus, authentication system, authentication method, and authentication program using biometric information for authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current authentication systems for multi-function peripherals (MFPs) do not allow multiple logins by the same user, either through identity authentication using biometrics or owner authentication with IC cards, preventing registered users from simultaneously logging in and delegating operations to unregistered individuals.

Innovation Solution

An authentication apparatus and system that stores user records with both identity and owner authentication information, enabling comparison and permission signals for multiple logins across connected information processing devices, allowing simultaneous login and delegation of operations while maintaining security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If identity authentication using biometrics is performed, then authentication security is improved, but multiple logins by the same user are not allowed

Engineering Contradiction:
Improveauthentication securityVSAvoidmultiple login capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The authentication system is segmented into two distinct authentication methods: identity authentication (biometrics) and owner authentication (IC card). Each authentication method has its own permission portion that independently manages login permissions. This segmentation allows the system to maintain security through biometric verification while simultaneously enabling multiple logins through IC card delegation, resolving the contradiction between security and multiple login capability.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If owner authentication with IC card is performed, then delegation to unregistered persons is enabled, but authentication security is reduced

Engineering Contradiction:
Improvedelegation capabilityVSAvoidauthentication security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The IC card serves as an intermediary that enables delegation of authentication permissions to unregistered persons. When the registered user authenticates via biometrics, they can issue permission signals to others using their IC card. The IC card acts as a mediator that transfers authentication rights without compromising the original biometric security verification, allowing delegation while maintaining the security foundation.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If multiple authentication methods are implemented, then user convenience is improved, but system complexity increases

Engineering Contradiction:
Improveuser convenienceVSAvoidsystem complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The authentication apparatus is designed with multi-functionality, incorporating both identity authentication (biometrics) and owner authentication (IC card) within a single system. The storage portion stores both types of authentication information, and the system includes both identity authentication portion and owner authentication portion that work together. This universal design allows users to choose the most convenient authentication method for each situation, improving ease of operation while managing complexity through integrated design.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS8453259B2Authentication apparatus, authentication system, authentication method, and authentication program using biometric information for authentication
Publication Date: 2013.05.28 KONICA MINOLTA BUSINESS TECH INC
  • US8453259B2 patent drawing
  • US8453259B2 patent drawing
  • US8453259B2 patent drawing

AI summary

In order to enable multiple logins by a same user, the authentication server includes a registration portion to store a user record including a fingerprint image for authentication of identity of a user and owner authentication information stored in a IC card issued to the user; an identity authentication portion to compare a fingerprint image received from one of MFPs with the one included in the user record for authentication; a first permission portion to transmit a permission signal permitting login based on the authenticated fingerprint image to the MFP that transmitted the fingerprint image; an owner authentication portion to compare owner authentication information received from one of the MFPs with the one included in the user record for authentication; and a second permission portion to transmit a permission signal permitting login based on the authenticated owner authentication information to the MFP that transmitted the owner authentication information.