Distributed User Authentication in Multi-Device Image Processing Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional image-processing systems require a server for user control and access management, leading to complex system structures and inflexibility when adding new devices to a network.

Innovation Solution

An image-processing system where user identification information is stored on one of multiple connected devices, allowing other devices to execute functions possessed by the storage device, simplifying user-based function setting and access management without the need for a central server.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a server is provided for user control and access management, then user-based function setting is achieved, but system structure becomes complicated

Engineering Contradiction:
Improveuser-based function settingVSAvoidsystem structure
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent extracts the user control function from a separate server and embeds it directly into each image-processing apparatus. Each apparatus stores user identification information and executes functions based on stored registered-user information, eliminating the need for a central server while maintaining user-based access control.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

Each image-processing apparatus autonomously manages user authentication and function execution. The apparatuses self-determine whether to execute functions based on whether registered-user information is stored in them, without requiring external server intervention for access control decisions.

Inventive Principle:
Principle #25Self-service

2Reliability

If a server is provided for user control and access management, then access control function is achieved, but system structure becomes complicated

Engineering Contradiction:
Improveaccess control functionVSAvoidsystem structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The access control function is extracted from the server and distributed to individual apparatuses. Each apparatus contains its own access control mechanism that checks whether registered-user information is stored in the apparatus before permitting function execution, thereby maintaining reliable access control without server dependency.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If network address of server is stored in newly connected apparatus, then access to server is enabled, but system amendment flexibility is reduced

Engineering Contradiction:
Improveaccess to serverVSAvoidsystem amendment flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The dependency on server network address is extracted and eliminated. Each apparatus independently stores and processes registered-user information locally, enabling new apparatuses to join the network without requiring configuration of server addresses. The system automatically adapts to new devices without manual setup.

Inventive Principle:
Principle #2Taking out (Extraction)

4Adaptability or versatility

If user identification information is stored in multiple apparatuses, then flexible access is enabled, but data management complexity increases

Engineering Contradiction:
Improveflexible accessVSAvoiddata management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The user identification information is segmented and stored individually in each apparatus rather than centralized. Each apparatus maintains its own copy of registered-user information, allowing independent access control decisions. This segmentation simplifies data management by distributing the burden across multiple small storage units rather than one large centralized system.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS8151361B2Image-processing system enabling user to use a plurality of communicably connected image-processing apparatuses, image-processing apparatus, function execution authorizing method, and function execution authorizing program embodied in computer readable medium
Publication Date: 2012.04.03 KONICA MINOLTA BUSINESS TECH INC
  • US8151361B2 patent drawing
  • US8151361B2 patent drawing
  • US8151361B2 patent drawing

AI summary

In order to facilitate the setting of functions executable in each of a plurality of image-processing apparatuses that are communicably connected to one another, each of the MFPs, which are communicably connected to one another, stores registered-user information including at least user identification information in each HDD. When an operated terminal among the plurality of MFPs receives user identification information, the operated terminal judges whether its HDD stores registered-user information including the received user identification information. When judging in the affirmative, the operated terminal permits execution of the functions possessed by the operated terminal. When judging in the negative, the operated terminal acquires, from the MFP (home terminal) that stores registered-user information including the received user identification information, the function information of the home terminal, and permits execution of the functions, among the functions defined in the function information of the home terminal, that are also possessed by the operated terminal.