Remote MFD Authentication with Local Account Caching

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Enterprises face challenges in providing remote access to multi-function devices (MFDs) while preventing unauthorized use and ensuring timely retrieval of devices from remote locations.

Innovation Solution

An enterprise-owned MFD with a communication interface for remote authentication, a re-activation timer, and a de-activation timer, which allows remote authentication, local account creation, and scheduled pick-up after de-activation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If remote access to MFDs is enabled for employees, then productivity and accessibility are improved, but device security and unauthorized use prevention deteriorate

Engineering Contradiction:
Improveremote accessVSAvoiddevice security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

An authentication server acts as an intermediary between the MFD and remote users. The server verifies user credentials and manages authentication tokens, allowing secure remote access without compromising device security. The server mediates all authentication requests, ensuring that only authorized employees can access the MFD remotely.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The MFD performs self-authentication by automatically communicating with the authentication server to verify its identity and retrieve authentication tokens. The device manages its own security credentials and authentication state without requiring manual intervention, enabling secure remote access while maintaining device security through automated credential verification.

Inventive Principle:
Principle #25Self-service

2Productivity

If MFDs are deployed at remote locations, then employee productivity is improved, but device retrieval and cost management deteriorate

Engineering Contradiction:
Improveemployee productivityVSAvoiddevice retrieval
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The authentication server provides feedback to the MFD about authentication status and device deployment state. When an employee is no longer authenticated or leaves the enterprise, the server notifies the MFD to enter a restricted state, automatically triggering device retrieval scheduling. This feedback mechanism ensures timely retrieval without manual tracking, maintaining productivity while reducing retrieval time losses.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system preliminarily schedules device pickup before the device is actually needed back at the enterprise location. When authentication expires or is revoked, the system automatically initiates the retrieval process by scheduling pickup in advance, rather than waiting until the device is no longer needed. This preliminary action reduces retrieval time and ensures smooth device recovery.

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If local authentication accounts are created for remote users, then access convenience is improved, but device complexity and account management deteriorate

Engineering Contradiction:
Improveaccess convenienceVSAvoidaccount management
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The authentication server serves as an intermediary that centralizes account management for all remote users. Instead of managing accounts on each individual MFD, the server handles credential verification, token issuance, and account status management. This eliminates the need for complex local account management on each device while maintaining convenient local authentication through cached credentials.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system merges remote authentication with local authentication capabilities. The MFD caches authentication tokens received from the remote authentication server, allowing users to authenticate locally without continuous network connectivity. This combines the security of centralized authentication with the convenience of local access, reducing device complexity by eliminating the need for separate local account creation and management.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentEP4246356B1Remote authentication and local control of enterprise devices
Publication Date: 2025.06.04 XEROX CORP
  • EP4246356B1 patent drawingFigure 1
  • EP4246356B1 patent drawingFigure 2
  • EP4246356B1 patent drawingFigure 3

AI summary

An enterprise owned multi-function device (MFD) is disclosed. For example, the MFD includes, a communication interface to establish a communication session with an authentication server, a re-activation timer, a processor and a non-transitory computer readable medium storing instructions, which when executed by the processor, cause the processor to authenticate the enterprise owned MFD over the communication session when the enterprise owned MFD is activated at a remote location of an employee, create a local account of the employee for local authentication, and authorize access to the employee via the local account of the employee until the re-activation timer expires.