Conference Network Access Control via Terminal ID Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing information processing systems for managing digitized data in conference settings face challenges in ensuring security while improving convenience, particularly in wireless connections to electronic apparatuses connected to a network, as they require pre-registration and transmission of connection and authentication information, which is inconvenient.

Innovation Solution

The system implements a configuration where a wired or wireless network is provided in a conference room, with electronic apparatuses and portable terminals connected, using a short-range communications apparatus and a wireless apparatus to manage access and data sharing through a shared storage area, controlling access based on user levels and using SSID and IP address for secure connections.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If pre-registration and transmission of connection and authentication information is implemented, then security is ensured, but convenience deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidconvenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system performs preliminary actions by pre-registering terminal identification information and user information in the storage part before actual communication occurs. This allows the determination part to quickly authenticate terminals without requiring real-time complex verification, thus maintaining security while improving connection convenience.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediate authentication mechanism where the storage part and determination part act as mediators between the terminal apparatuses and the communication system. The terminal identification information serves as an intermediary credential that enables secure authentication without requiring direct complex verification processes, resolving the contradiction between security and convenience.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If access control based on terminal identification information is implemented, then security is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments the authentication and access control functions into distinct modular components: a storage part for storing terminal identification information, a determination part for verifying credentials, and a control part for managing access. This segmentation allows each component to perform its specific function efficiently, maintaining security while reducing overall system complexity through functional separation.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent utilizes parameter changes by storing and comparing terminal identification information (such as MAC addresses or other unique identifiers) as key parameters for authentication. By changing the authentication parameter from complex multi-factor verification to simple identifier matching, the system maintains security requirements while significantly reducing device complexity.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentEP3068098B1Information processing system, and information processing method
Publication Date: 2019.10.09 RICOH CO LTD
  • EP3068098B1 patent drawingFigure 1
  • EP3068098B1 patent drawingFigure 2~3
  • EP3068098B1 patent drawingFigure 4~5

AI summary

An information processing system transmits, via a first network, connection information for a second network that is different from the first network to a plurality of terminal apparatuses; carries out communications with the terminal apparatuses via the second network based on the transmitted connection information; stores respective items of terminal identification information for the terminal apparatuses, with which the communications are carried out via the second network; determines whether the terminal apparatuses that are identified by the stored items of terminal identification information can carry out communications via the second network; and, when determining that the terminal apparatuses cannot carry out communications via the second network, carries out such control as to prevent the second network from being used to carry out communications.