Network Management Authentication Segmentation for Plug-in Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing management software for network devices using SNMP does not effectively manage authentication information for different management purposes, particularly when extended by plug-in software, leading to inconsistencies and security concerns.

Innovation Solution

A management apparatus and method that includes separate storing units for authentication information used by primary and plug-in management software, allowing each to register and set authentication information independently, ensuring secure and purpose-specific management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If separate authentication information management is implemented for management software and plug-in software, then security and purpose-specific management are improved, but device complexity and information management overhead increase

Engineering Contradiction:
ImprovesecurityVSAvoidinformation management overhead
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent divides authentication information management into separate storage units: one for management software and another for plug-in software. This segmentation allows each software component to manage its own authentication information independently, improving security through isolation while maintaining clear purpose-specific management boundaries.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a registration unit as an intermediary mechanism that coordinates between the first management software and the second plug-in software. This registration unit manages the mapping between devices and authentication information, reducing the complexity overhead by providing a centralized coordination point rather than requiring direct complex interactions between multiple software components.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If plug-in software independently manages authentication information, then adaptability and versatility are improved, but loss of information and inconsistency between software components increase

Engineering Contradiction:
Improvepurpose-specific managementVSAvoidauthentication information consistency
Core Design Contradiction:
Adaptability or versatilityVSLoss of information

Solution Approach 1:

The patent creates a universal registration unit that serves both the management software and the plug-in software. This registration unit maintains device information and authentication information mappings that are accessible to both software components, ensuring consistency while allowing each software to independently manage its specific authentication requirements for different purposes.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The registration unit provides feedback mechanisms that allow the plug-in software to query and verify authentication information consistency with the management software. This feedback loop ensures that authentication information remains consistent across different software components while maintaining the adaptability needed for purpose-specific management.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS8966076B2Management apparatus, management method, and computer-readable medium
Publication Date: 2015.02.24 CANON KK
  • US8966076B2 patent drawing
  • US8966076B2 patent drawing
  • US8966076B2 patent drawing

AI summary

A management apparatus that causes control unit to execute first management software for managing a plurality of devices on a network comprises: a first storing unit which stores authentication information to be used to access a device using a function of the first management software; a second storing unit configured to store authentication information to be used to access the device using a function of second management software that is added to the first management software to add a new function; a registration unit configured to register the device to be managed by the second management software; and a second setting unit configured to set the authentication information to be used to access the device using the function of the second management software.