Secure User Authentication via Encrypted ID Transmission
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current information management systems for image processing apparatuses lack secure user authentication and job execution mechanisms, particularly when user IDs are managed by both the image processing apparatus and the mobile terminal, leading to potential security vulnerabilities such as unauthorized access and the need for repeated user ID registration upon device exchange.
Innovation Solution
An information management control apparatus with a storage unit, transmission unit, and permission unit, utilizing a pair of keys for encryption and decryption, where the mobile terminal transmits a print job with a public key and email address, and the image processing apparatus encrypts and decrypts user IDs using these keys for secure authentication and job execution.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If user ID is managed by both image processing apparatus and mobile terminal, then user authentication can be performed, but security vulnerabilities such as unauthorized access occur
Solution Approach 1:
The patent extracts the user ID management function from the image processing apparatus and relocates it exclusively to the mobile terminal. The image processing apparatus no longer stores or manages user IDs, instead receiving only encrypted authentication data from the mobile terminal. This extraction eliminates the security vulnerability of dual management while preserving authentication capability.
Solution Approach 2:
The patent introduces encryption as an intermediary mechanism between the mobile terminal and image processing apparatus. The mobile terminal encrypts the user ID using a public key before transmission, and the image processing apparatus decrypts it using a private key. This intermediary encryption layer prevents unauthorized access while enabling secure authentication.
2Ease of operation
If user ID is stored in image processing apparatus, then authentication can be performed, but repeated registration is needed upon device exchange
Solution Approach 1:
The patent performs preliminary action by storing the user ID and public key in the mobile terminal before any image processing operations. When the user exchanges devices or needs to authenticate, the mobile terminal already possesses the necessary authentication credentials, eliminating the need for repeated registration. The image processing apparatus only needs to receive and verify the encrypted user ID.
3Extent of automation
If image processing apparatus manages user IDs, then job execution can be controlled, but security vulnerabilities increase
Solution Approach 1:
The patent extracts the user ID storage and management functions from the image processing apparatus, leaving only the job execution control functions. The apparatus retains the ability to control job execution through encrypted authentication verification, while the vulnerable user ID management is completely removed and relocated to the mobile terminal.
Solution Approach 2:
The mobile terminal performs self-service by autonomously managing user ID storage, public key generation, and encryption of authentication data. The image processing apparatus simply receives the encrypted data and verifies it using its private key, without needing to manage user IDs itself. This self-service approach maintains automation while improving security.
Data Source
AI summary
An information management control apparatus includes a storage unit, a transmission unit, and a permission unit. The storage unit stores a job including one of a pair of keys, with which both encryption and decryption are possible, and address information. The transmission unit encrypts a user ID of a login user by using the one of the keys and transmits the encrypted user ID through a communication unit in accordance with the address information, the user having been logged in in order to issue an instruction for executing the job. The permission unit permits execution of the job, in a case in which a user ID that has been encrypted by using the other of the keys and transmitted in response to the transmission is decrypted by using the one of the keys, if the user ID is the same as the user ID of the login user.


