Image Processing Apparatus Distributed Authentication Session Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Multifunction printers (MFPs) face challenges in managing user authentication sessions effectively, leading to issues like unauthorized access and inaccurate accounting, due to their inability to strictly manage authentication and session management, which results in performance degradation and scalability problems when handling multiple nodes or processing queues.

Innovation Solution

An image processing apparatus is designed with a receiving unit for service requests, an authentication request unit for authenticating users, an execution unit for executing services based on authentication results, and a management unit for managing both execution and authentication states, allowing for secure and scalable session management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If centralized authentication server is used to manage all network service sessions, then authentication security is improved, but processing performance and scalability deteriorate when there are many nodes or processing queues

Engineering Contradiction:
Improveauthentication securityVSAvoidprocessing performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent segments the centralized authentication server into distributed authentication management across multiple image processing apparatuses. Each apparatus maintains its own authentication state locally, eliminating the single-point bottleneck while preserving security through distributed verification of authentication states.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an authentication state management mechanism that acts as an intermediary between service requests and authentication verification. This mediator tracks authentication states locally and provides rapid verification without requiring constant communication with external authentication servers, improving processing speed while maintaining security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If centralized authentication server manages all sessions, then authentication control is improved, but system scalability deteriorates when adding new services or nodes

Engineering Contradiction:
Improveauthentication controlVSAvoidsystem scalability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements a universal authentication state management mechanism that can handle multiple service types and authentication scenarios through a common local state tracking system. This allows new services and nodes to be added without modifying the core authentication control logic, enhancing both scalability and adaptability while maintaining reliable authentication control.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If automatic logout after timeout is implemented, then security against masquerade is improved, but user convenience deteriorates due to session management restrictions

Engineering Contradiction:
Improvesecurity against masqueradeVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements dynamic session management where timeout periods and logout policies can be adjusted based on service type, user role, and activity patterns. This dynamic approach maintains security against masquerade through enforced session limits while improving user convenience by adapting to different operational contexts and reducing unnecessary logouts for active users.

Inventive Principle:
Principle #15Dynamics

4Reliability

If session management is strictly enforced for each job, then security against unauthorized access is improved, but processing complexity increases

Engineering Contradiction:
Improvesecurity against unauthorized accessVSAvoidprocessing complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges authentication state management with job processing workflows by integrating state tracking into the existing service request handling process. This unified approach enforces strict session management for security while reducing processing complexity by eliminating separate authentication verification steps and consolidating state management within the job processing pipeline.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS8640193B2Image processing apparatus, method for controlling the same, program, and storage medium
Publication Date: 2014.01.28 CANON KK
  • US8640193B2 patent drawing
  • US8640193B2 patent drawing
  • US8640193B2 patent drawing

AI summary

An image processing apparatus for providing at least a service to a service requester receives a service execution request and authentication information of a service requester from the service requester and issues a request for authenticating the service requester to an authentication service. Also, the image processing apparatus executes the requested service based on an authentication result transmitted from the authentication service. Further, the image processing apparatus manages an execution state of the executed service and an authentication state of the service requestor by associating the execution state with the authentication state.