MFP Authentication Segmentation for Remote UI Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Communication apparatuses, such as multi-function peripherals (MFPs), face the risk of improper access to server apparatuses via remote UIs when authentication information is saved within the device, potentially leading to leakage of sensitive user information.

Innovation Solution

The communication apparatus is designed to accept operations for setting transmission destinations, obtain authentication information to log into a server, and provide a screen for inputting authentication information externally without using stored authentication information, thereby preventing unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If authentication information is saved in the communication apparatus for server access, then convenient server communication is achieved, but the risk of improper access and information leakage via remote UI increases

Engineering Contradiction:
Improveserver access convenienceVSAvoidimproper access risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent segments the authentication process by distinguishing between local UI operations (which can use saved authentication information) and remote UI operations (which require fresh authentication). This segmentation allows the system to maintain convenience for local users while preventing unauthorized remote access, resolving the contradiction between ease of operation and security risk.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies different authentication policies to different access interfaces: the local UI is configured to use saved authentication information for convenience, while the remote UI is configured to require new authentication input. This local quality approach allows each interface to have optimized security characteristics appropriate to its usage context, eliminating the need to choose between overall convenience and overall security.

Inventive Principle:
Principle #3Local quality

2Adaptability or versatility

If authentication information is provided via remote UI, then external apparatus can access server functions, but the possibility of information leakage increases

Engineering Contradiction:
Improveremote access capabilityVSAvoidinformation leakage risk
Core Design Contradiction:
Adaptability or versatilityVSLoss of information

Solution Approach 1:

The patent requires authentication information to be input fresh at the time of remote access operation, rather than using pre-saved credentials. This preliminary action of re-authentication ensures that even if authentication information is compromised, it cannot be used for unauthorized remote access, maintaining remote accessibility while preventing information leakage.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary authentication mechanism that mediates between the remote UI and the saved authentication information. Instead of directly using saved credentials, the system requires an intermediate authentication step where the user must input credentials through the remote UI, creating a security barrier that prevents direct access while maintaining functionality.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Device complexity

If the same authentication policy is applied to both local UI and remote UI, then policy simplicity is maintained, but security risks specific to remote access cannot be addressed

Engineering Contradiction:
Improveauthentication policy complexityVSAvoidaccess security
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent makes the authentication policy dynamic by allowing different authentication behaviors for different UI types. The system automatically adjusts its authentication requirements based on whether the operation originates from local UI or remote UI, enabling flexible security management without requiring complex manual configuration. This dynamic approach maintains operational simplicity while achieving differentiated security protection.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS10965669B2Communication apparatus, method of controlling the same, and storage medium
Publication Date: 2021.03.30 CANON KK
  • US10965669B2 patent drawing
  • US10965669B2 patent drawing
  • US10965669B2 patent drawing

AI summary

An MFP (communication apparatus) accepts, as an operation for making an electronic data transmission destination setting, an operation using a local UI (LUI) or a remote UI (RUI). The MFP, in accordance with an accepted operation, logs in to an LDAP server (server apparatus), and performs obtainment processing for obtaining a transmission destination from the server. If logging in to the LDAP server in accordance with an operation using the LUI in the obtainment processing, the MFP uses authentication information stored in an HDD, and if logging in to the LDAP server in accordance with an operation using the RUI, the MFP does not use authentication information stored in the HDD.