Image Processing Apparatus Authentication Token Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Multi-function peripherals store user IDs and passwords internally, risking exposure if the device malfunctions and requires external repair, with no mechanism to prevent retention of authentication information within the device.

Innovation Solution

An image processing apparatus with a wireless communication interface, storage for identification information, and a processor that switches operational modes based on authentication responses from a server, ensuring that identification information is not retained if the device malfunctions, and only authorized users can access functions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If user ID and password are stored in the built-in DB for authentication, then authentication function is enabled, but security is worsened because the authentication information may be exposed if the device malfunctions

Engineering Contradiction:
Improveauthentication functionVSAvoiddata leakage risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the authentication information (user ID and password) from the device's internal storage and relocates it to the authentication server. The device only stores a token that represents the authentication state, while the actual authentication credentials are maintained externally on the server, thereby eliminating the risk of credential exposure through device malfunction.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an authentication server as an intermediary between the device and the authentication system. Instead of storing authentication information locally, the device communicates with the server through this intermediary to perform authentication, which centralizes security control and prevents local storage of sensitive credentials.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If all authentication information is stored in the device for self-contained operation, then device independence is improved, but security is worsened due to inability to delete authentication data

Engineering Contradiction:
Improvedevice independenceVSAvoidauthentication data management
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent extracts authentication information from the device and stores it on the authentication server. This allows the device to operate independently for token storage and authentication requests, while the server maintains centralized control over authentication credentials, enabling proper data management and deletion capabilities.

Inventive Principle:
Principle #2Taking out (Extraction)

3Ease of operation

If authentication information is stored in the device to enable function execution, then function accessibility is improved, but security is worsened because the information remains in the device even after malfunction

Engineering Contradiction:
Improvefunction accessibilityVSAvoidunauthorized access risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent extracts authentication credentials from device storage and relocates them to the authentication server. The device maintains ease of operation by storing tokens that enable function execution, while the actual sensitive authentication information is secured on the server, preventing unauthorized access even if the device malfunctions.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent implements preliminary authentication where the device must first authenticate with the server before executing any functions. This preliminary action ensures that even if authentication information were stored locally, it would be protected by prior verification with the server, preventing unauthorized function execution.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10257387B2Image processing apparatus and information management method
Publication Date: 2019.04.09 BROTHER KOGYO KK
  • US10257387B2 patent drawing
  • US10257387B2 patent drawing
  • US10257387B2 patent drawing

AI summary

An image processing apparatus includes: an image processing device processing image data; a wireless communication wirelessly communicating with an external terminal present at a predetermined distance from the wireless communication and receiving first identification information from the external terminal; a first storage storing a first record including the first identification information and second identification information while being associated with each other; an receiving the second identification information and third identification information; a communication capable of communicating with a server, the server storing the second identification information and the third identification information while being associated with each other; a display; and a processor. The processor is configured to switch an operational mode of the image processing apparatus between a first mode for causing the image processing apparatus to standby, and a second mode in which a processing by the image processing device is executable.