Authentication Synchronization via Policy Filtering

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In scenarios where virtual devices are synchronized with real devices across different security levels, authentication information with a looser policy may not comply with stricter policies on the cloud, leading to potential security breaches during synchronization.

Innovation Solution

An information processing apparatus and service providing system that acquires and synchronizes authentication information by transmitting only compliant data between devices, ensuring that authentication policies are aligned, even across different security levels, by using a processor to manage and synchronize user information between a virtual device and a real device via a communication line through a firewall.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If authentication information is synchronized between real device and virtual device without policy verification, then synchronization speed is improved, but security compliance deteriorates

Engineering Contradiction:
Improvesynchronization speedVSAvoidsecurity compliance
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system performs preliminary verification of authentication policy compliance before synchronizing authentication information. The information processing apparatus checks whether the authentication information meets the authentication policy requirements of the virtual device prior to transmission, preventing non-compliant data from being synchronized in the first place.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The information processing apparatus acts as an intermediary between the real device and virtual device, filtering and verifying authentication information before it reaches the virtual device. This mediator role ensures that only compliant authentication information is transmitted, maintaining security policies while enabling synchronization.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If strict authentication policy verification is performed before synchronization, then security compliance is improved, but synchronization efficiency deteriorates

Engineering Contradiction:
Improvesecurity complianceVSAvoidsynchronization efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system implements self-service verification where the information processing apparatus autonomously checks authentication policy compliance without requiring manual intervention or complex external verification processes. This automated self-verification maintains security compliance while minimizing overhead and preserving synchronization efficiency.

Inventive Principle:
Principle #25Self-service

3Quantity of substance

If authentication information from looser policy environment is transmitted to stricter policy environment, then data completeness is improved, but policy compliance deteriorates

Engineering Contradiction:
Improvedata completenessVSAvoidpolicy compliance
Core Design Contradiction:
Quantity of substanceVSReliability

Solution Approach 1:

The system changes the parameter of authentication information by verifying and filtering based on the target authentication policy before transmission. Instead of transmitting all authentication information regardless of compliance, the system adapts the transmitted data set to meet the stricter policy requirements of the virtual device, ensuring both completeness of compliant data and policy adherence.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS20240163286A1Information processing apparatus and service providing system
Publication Date: 2024.05.16 FUJIFILM BUSINESS INNOVATION CORP
  • US20240163286A1 patent drawing
  • US20240163286A1 patent drawing
  • US20240163286A1 patent drawing

AI summary

The information processing apparatus includes a processor configured to: acquire specified information that specifies a rule of first authentication information for each user used for authentication of the user, from a remote apparatus connected by a communication line via a firewall; and synchronize the first authentication information and second authentication information stored in the remote apparatus by transmitting the first authentication information compliant with the specified information among the first authentication information to the remote apparatus.