IC Card Authentication State Management for Secure Processing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The use of IC cards without encryption processors poses security risks as the private key can remain in external devices, and those with encryption processors require the card to remain inserted for processing, leading to potential unauthorized use when the user is away.

Innovation Solution

An information processing apparatus with a user authentication unit, data processor, processing completion detector, and verification state changing unit that authenticates users, performs private key processing, and notifies users when the processing is complete, allowing the IC card to be safely removed.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If an encryption processor equipped IC card is used to enhance security by prohibiting private key readout, then security is improved, but the IC card must remain inserted in the device during processing which increases the risk of unauthorized use

Engineering Contradiction:
ImprovesecurityVSAvoidunauthorized use risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements dynamic state management of the IC card authentication status. The authentication unit changes the authentication state based on processing completion status - maintaining authenticated state during processing and transitioning to unauthenticated state after completion. This dynamic adjustment resolves the contradiction by keeping the card inserted for security during processing while automatically reducing unauthorized use risk after processing ends.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent employs feedback mechanisms where the authentication unit continuously monitors the processing status and adjusts the authentication state accordingly. When processing is detected as complete, the system provides feedback to revoke authentication automatically. This feedback loop ensures that security is maintained during processing while preventing unauthorized use after processing completion.

Inventive Principle:
Principle #23Feedback

2Ease of operation

If the IC card is removed after authentication to allow user mobility, then ease of operation is improved, but the private key processing cannot be completed and security is compromised

Engineering Contradiction:
Improveuser mobilityVSAvoidprocessing completion
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements preliminary notification to the user before authentication is revoked. The notification unit alerts the user that processing is complete and the card can be removed. This allows the user to plan their actions accordingly - either removing the card immediately or staying for brief notification periods. The preliminary action resolves the contradiction by providing user awareness and control over when to remove the card after processing completes.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system provides self-service functionality where the authentication state is automatically managed based on processing status without requiring manual user intervention. The authentication unit automatically revokes access when processing completes, and the notification unit informs the user. This self-managed system resolves the contradiction by automatically balancing processing completion requirements with user mobility needs.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS8302184B2Information processing apparatus, information processing method and storage medium
Publication Date: 2012.10.30 FUJIFILM BUSINESS INNOVATION CORP
  • US8302184B2 patent drawing
  • US8302184B2 patent drawing
  • US8302184B2 patent drawing

AI summary

An information processing apparatus includes a user authentication unit that authenticates a user in a condition where an authentication medium used for authenticating the user is inserted, the authentication medium storing personal identification information of the user, a private key, and a software program for using the private key and including a processor for running the software program, to thereby establish a verified state in which the user is allowed to use the apparatus, a data processor that performs data processing including private key processing, a processing completion detector that detects completion of the private key processing performed by the data processor, and a verification state changing unit that changes, the verified state of the user having been established as a result of authenticating the user to a user unverified state based on detection of the completion of the private key processing in the processing completion detector.