Certificate Holding Authentication for Expired Network Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing authentication systems degrade user convenience when access rights are uniformly invalidated after a validity term expires, lacking a simple method to ensure security while maintaining user convenience.

Innovation Solution

An authentication system that includes a hardware processor and a certificate issuing server, which allows the storage of previously valid certificates for reconnection when identical certificates are presented, subject to additional conditions, thereby permitting network access without immediate certificate reissuance.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If access rights are uniformly invalidated after expiration of the validity term, then security is ensured, but user convenience is degraded

Engineering Contradiction:
ImprovesecurityVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The authentication server performs preliminary verification by checking the certificate holding part for previously valid certificates before completely invalidating access. This preliminary action allows the system to maintain security while preserving user convenience for legitimate users whose certificates have expired but were previously validated.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system changes the authentication parameter from a binary valid/invalid state to a multi-state verification process that includes checking the certificate holding part. This parameter change enables differentiated treatment: completely invalidating unauthorized access while allowing renewed access for users with previously valid certificates, thus resolving the contradiction between security and user convenience.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If certificates are strictly validated with expiration checks, then security is maintained, but administrative complexity increases due to frequent reissuance requirements

Engineering Contradiction:
ImprovesecurityVSAvoidadministrative complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication server performs preliminary verification by checking the certificate holding part for previously valid certificates before completely invalidating access. This preliminary action allows the system to maintain security while preserving user convenience for legitimate users whose certificates have expired but were previously validated.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system creates a functional copy of the certificate validation process by checking the certificate holding part, which stores previously valid certificates. This copying mechanism allows the system to verify user identity without requiring immediate reissuance of certificates, thereby reducing administrative complexity while maintaining security through the stored certificate verification.

Inventive Principle:
Principle #26Copying

3Reliability

If uniform certificate invalidation is implemented, then security is ensured, but time loss increases due to required reauthentication

Engineering Contradiction:
ImprovesecurityVSAvoidreauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The authentication server performs preliminary verification by checking the certificate holding part for previously valid certificates before completely invalidating access. This preliminary action allows the system to maintain security while preserving user convenience for legitimate users whose certificates have expired but were previously validated.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system maintains continuity of useful action by allowing users with previously valid certificates (stored in the certificate holding part) to continue accessing the second network without immediate reauthentication. This continuous access for legitimate users reduces time loss while security is maintained through the preliminary verification process.

Inventive Principle:
Principle #20Continuity of useful action

Data Source

PatentUS12413572B2Authentication system, authentication method, and authentication program
Publication Date: 2025.09.09 KONICA MINOLTA INC
  • US12413572B2 patent drawing
  • US12413572B2 patent drawing
  • US12413572B2 patent drawing

AI summary

An authentication system includes: an information processing apparatus; a hardware processor that is connected to the apparatus via a first network and determines propriety of connection to a second network; and a certificate issuing server that is connected to the hardware processor via the second network and issues a certificate including a valid period and permitting the apparatus to connect to the second network, wherein the hardware processor includes a certificate holding part that holds a certificate with which connection has been permitted in a past, verifies a certificate transmitted from the apparatus and determines propriety of connection to the second network, verifies a valid period of a certificate transmitted from the apparatus, permits connection to the second network when the certificate is valid, determines, when the certificate is invalid, whether an identical certificate is held, and permits connection to the second network based on a determination result.