Dual Authentication System for Cloud Service Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cloud service providers face security risks when offering services to users authenticated with low security levels, as existing methods do not adequately ensure the safety of user authentication across different services.

Innovation Solution

An information processing system that employs dual authentication methods, where a first authentication method with higher security is used to authenticate users, and a second method with lower security is also utilized, with a condition-based association of user identification information to enhance security levels and prevent unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a service is provided to a user authenticated in another service without restriction, then service accessibility is improved, but service safety deteriorates

Engineering Contradiction:
Improveservice accessibilityVSAvoidservice safety
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent applies local quality by differentiating authentication requirements based on the service being accessed. Different security levels are assigned to different services, and users are subjected to appropriate authentication methods corresponding to each service's security requirements. This resolves the contradiction by allowing broad service accessibility while maintaining service-specific safety standards.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent implements dynamic authentication where the authentication method and security level are adjusted based on the user's authentication status in other services and the specific service being accessed. The system dynamically determines whether to apply first authentication (higher security) or second authentication (lower security) methods, enabling both service accessibility and safety to be maintained through adaptive security measures.

Inventive Principle:
Principle #15Dynamics

2Reliability

If dual authentication methods with condition-based association are implemented, then service safety is improved, but device complexity increases

Engineering Contradiction:
Improveservice safetyVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by pre-establishing association relationships between user identification information from different authentication methods. The system pre-judges whether users authenticated by a first authentication method satisfy conditions determined by a second authentication method, and pre-associates their user IDs. This reduces real-time processing complexity while maintaining high service safety through advance preparation.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If users authenticated by first authentication method are limited for service provision, then service safety is improved, but service productivity decreases

Engineering Contradiction:
Improveservice safetyVSAvoidservice provision efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements dynamic service provision where users authenticated by the first authentication method are selectively provided services based on whether they satisfy conditions determined by the second authentication method. This dynamic approach ensures service safety by limiting access to qualified users while maintaining productivity by providing services to those who meet the criteria, avoiding unnecessary restrictions.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS11595400B2Information processing system, information processing apparatus, and non-transitory computer readable medium storing program
Publication Date: 2023.02.28 FUJIFILM BUSINESS INNOVATION CORP
  • US11595400B2 patent drawing
  • US11595400B2 patent drawing
  • US11595400B2 patent drawing

AI summary

An information processing system includes: a first authentication unit that authenticates a user by a first method; a first providing unit that provides a service to the user authenticated by the first authentication unit; a second authentication unit that authenticates a user by a second method; and a second providing unit that provides a service to the user authenticated by the second authentication unit and also provides a service to the user authenticated by the first authentication unit in a case where the first method satisfies a condition determined according to the second method.