Authentication Processing Apparatus with Dual Units for FIPS Transition

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Devices upgraded to support Federal Information Processing Standards (FIPS) mode face issues with authentication information management, as they cannot decrypt authentication information encrypted using compromised algorithms, leading to inconsistent authentication processing and the need for manual resetting across multiple devices.

Innovation Solution

An information processing apparatus employs a first and second authentication unit to manage authentication information, where the first unit processes second authentication information obtained by encrypting first information received from a terminal, and the second unit enables the use of this information for authentication, allowing seamless transition to FIPS mode without manual resetting.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a device is upgraded to support FIPS mode, then security compliance is improved, but authentication processing becomes inconsistent because the device cannot decrypt authentication information encrypted using compromised algorithms

Engineering Contradiction:
Improvesecurity complianceVSAvoidauthentication processing
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent applies preliminary action by performing authentication using the old encryption method before the FIPS mode transition, capturing the authentication result in advance. This allows the system to switch to FIPS mode without losing authentication functionality, as the preliminary authentication result is retained and can be used after the transition when old encryption methods are no longer available.

Inventive Principle:
Principle #10Preliminary action

2Ease of operation

If authentication information is encrypted using compromised algorithms for backward compatibility, then ease of operation is improved, but reliability deteriorates because the encrypted information cannot be decrypted after upgrading to FIPS mode

Engineering Contradiction:
Improvebackward compatibilityVSAvoidauthentication information validity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system performs authentication using the compromised algorithm in advance before the FIPS mode upgrade, capturing the authentication result. This preliminary action ensures that authentication can proceed using the old method when still available, and the result is preserved for use after the upgrade when the old method is no longer supported.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If multiple target devices require authentication resetting after FIPS mode upgrade, then security compliance is improved, but loss of time increases due to the need for manual resetting processes

Engineering Contradiction:
Improvesecurity complianceVSAvoidauthentication resetting time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs authentication using the old encryption method in advance before the FIPS mode upgrade, capturing the authentication result beforehand. This eliminates the need for manual resetting after the upgrade, as the preliminary authentication result is already available and can be used across multiple devices without requiring time-consuming re-authentication.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12395345B2Information processing apparatus and control method therefor
Publication Date: 2025.08.19 CANON KK
  • US12395345B2 patent drawing
  • US12395345B2 patent drawing
  • US12395345B2 patent drawing

AI summary

An information processing apparatus that executes authentication processing using authentication information received from a terminal includes a first authentication unit configured to execute first authentication processing using second authentication information and preliminarily managed authentication information, the second authentication information being obtained by encrypting first authentication information received from the terminal, and a second authentication unit configured to execute second authentication processing different from the first authentication processing, wherein, in a case where the second authentication information is authenticated by the first authentication unit, the first authentication information is managed to be usable by the second authentication unit.