Device Management System Biometric Authentication via Intermediary Server

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network devices face challenges in securely allowing access to special modes for maintenance operations, as general users can potentially misuse special commands, and biometric authentication methods require pre-registration on all devices, making it impractical for temporarily dispatched users.

Innovation Solution

A system comprising a terminal with an authentication module and tamper-resistant storage for biometric information, a network device with communication capabilities, and a device management system that uses a public key corresponding to a secret key to verify user authentication, allowing only authorized users to access special modes by generating and verifying signatures.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If biometric information is pre-registered on all network devices for authentication, then authentication security is improved, but device complexity and operational burden increase significantly

Engineering Contradiction:
Improveauthentication securityVSAvoidregistration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a server as an intermediary between the terminal and network devices. The server manages biometric information storage and authentication logic, allowing terminals to authenticate without direct registration on each network device. This mediator approach resolves the contradiction by maintaining security while eliminating the need for terminals to register on multiple devices.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent shifts the authentication architecture from a distributed registration model (terminal registers on each device) to a centralized service model (terminal registers once with server, server issues credentials). This dimensional change in system architecture resolves the complexity issue while maintaining security through server-mediated authentication.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Ease of operation

If general users can access special modes without strict authentication, then ease of operation is improved, but security and risk of misuse increase

Engineering Contradiction:
Improveaccess easeVSAvoidmisuse risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent uses temporary authentication credentials (one-time tokens or time-limited keys) issued by the server to terminals. These disposable credentials provide strong authentication without requiring permanent biometric storage on devices. The credentials expire after use, preventing reuse and reducing the impact of potential breaches, thus maintaining security while enabling easy operation.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Solution Approach 2:

The server performs preliminary authentication verification before allowing access to special modes. By pre-verifying the terminal's authentication status and issuing appropriate credentials in advance, the system ensures security is established before operation begins, eliminating the need for complex ongoing authentication while preventing misuse.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If biometric information is stored on network devices for authentication, then authentication capability is improved, but information leakage risk increases

Engineering Contradiction:
Improveauthentication capabilityVSAvoidbiometric information leakage
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent extracts biometric information storage from the network devices and relocates it to a centralized server. The terminal only stores a reference or token, not the actual biometric data. This extraction eliminates the security risk of biometric information being stored on multiple network devices while maintaining authentication capability through server-based verification.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

Instead of storing actual biometric information on network devices, the system uses copies or references (authentication tokens) that can be verified without exposing the original biometric data. The server holds the master biometric data, and terminals receive verified copies or tokens for authentication purposes, preventing information leakage while maintaining authentication functionality.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS10984084B2System, device management system, and methods for the same
Publication Date: 2021.04.20 CANON KK
  • US10984084B2 patent drawing
  • US10984084B2 patent drawing
  • US10984084B2 patent drawing

AI summary

A device management system according to the present invention transmits, in response to an authentication request from a network device, verification data generated by the device management system and a whitelist including identification information corresponding to a user managed in association with the network device, receives a signature generated according to biometrics for a user on a portable terminal and the whitelist, via the network device, and, in a case where verification of the signature is successful, responds to the network device to permit login by the user of the terminal.