Network Equipment P2P Access Control via User Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network equipment for image forming apparatuses, such as MFPs, face challenges in balancing convenience and security for P2P connections, particularly in managing user access and preventing unauthorized access that could lead to information leakage.

Innovation Solution

The network equipment employs a control program executed by a processor to manage user identification and authentication, allowing automatic connections for administrator users while requiring authentication for guest users, thereby controlling direct communication between the MFP and portable terminals via wired and wireless LAN networks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If automatic connection is enabled for all users to simplify login, then ease of operation improves, but security deteriorates due to unauthorized access risks

Engineering Contradiction:
Improvelogin processVSAvoidaccess security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent applies local quality by differentiating authentication requirements based on user roles. Administrator users receive automatic connection privileges without authentication, while guest users are required to perform user authentication. This localized differentiation of access policies resolves the contradiction by providing ease of operation for administrators while maintaining security for guest users.

Inventive Principle:
Principle #3Local quality

2Reliability

If user authentication is required for all direct communications, then security improves, but ease of operation deteriorates due to complex login processes

Engineering Contradiction:
Improveaccess securityVSAvoidlogin process
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent segments users into distinct categories: administrator users and guest users. This segmentation allows the system to apply different authentication policies to different user groups. Administrator users are exempt from authentication requirements, while guest users are subject to authentication, thereby resolving the contradiction between security and ease of operation through user-based segmentation.

Inventive Principle:
Principle #1Segmentation

3Ease of operation

If direct communication via P2P connection is allowed without authentication, then ease of operation improves, but information security deteriorates due to potential unauthorized access

Engineering Contradiction:
Improveconnection establishmentVSAvoidunauthorized access
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent applies local quality by implementing location-specific (user-specific) authentication policies. For administrator users initiating direct communication, no authentication is required, providing ease of operation. For guest users, user authentication is mandatory before establishing direct communication, preventing unauthorized access. This user-specific policy differentiation resolves the contradiction between operational ease and security.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS10277599B2Network equipment and non-transitory computer readable storage medium
Publication Date: 2019.04.30 KYOCERA DOCUMENT SOLUTIONS INC
  • US10277599B2 patent drawing
  • US10277599B2 patent drawing
  • US10277599B2 patent drawing

AI summary

Provided is a network equipment that improves convenience of access from a portable terminal and security via a P2P connection. The network equipment includes a network control part, a user authentication part and a system control part. The network control part controls direct communication with the portable terminal. The user authentication part manages user identification information and user information by associating with each other. The system control part manages the administrator user with an automatic connection turned on and the guest user with the automatic connection turned off. IF an automatic connection is turned on, the system control part allows the direct communication. The system control part receives the user information from the portable terminal and causes the user authentication part to perform user authentication if the automatic connection is turned off, and allows the direct communication if the user authentication succeeded.