One-Time Password Authentication via BLE for Print Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing pull print services face challenges in securely authenticating users for printing jobs across different devices without exposing authentication information, particularly in scenarios where multiple users share output apparatuses and networks.

Innovation Solution

An output system and authentication method that generates and transmits a one-time password from an authentication service to an information processing device, which then communicates with an output apparatus using Bluetooth Low Energy (BLE) for authentication, minimizing the risk of authentication information leakage by limiting access and setting a validity period for the password.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a one-time password system is implemented for authentication, then security against unauthorized access is improved, but system complexity increases due to additional authentication components and protocols

Engineering Contradiction:
Improveauthentication securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

An authentication service acts as an intermediary between the output apparatus and the information processing device. The service generates one-time passwords and manages authentication credentials, allowing secure authentication without direct interaction between the output apparatus and user credentials, thus improving security while distributing system complexity across multiple components

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system uses one-time passwords as temporary copies of authentication credentials rather than requiring direct access to permanent credentials. Each one-time password is a single-use copy that validates authentication without exposing the master credentials, enhancing security while keeping the authentication mechanism relatively simple

Inventive Principle:
Principle #26Copying

2Ease of operation

If authentication information is transmitted through multiple devices, then ease of operation for location-free printing is improved, but the risk of authentication information leakage increases

Engineering Contradiction:
Improvelocation-free printing convenienceVSAvoidauthentication information leakage risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system employs one-time passwords that are disposable and valid for only a single authentication event. These short-lived credentials are generated, transmitted through the chain of devices (output apparatus to information processing device), used once for authentication, and then discarded, eliminating the risk of reuse attacks while maintaining operational convenience

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Solution Approach 2:

The authentication system uses time-limited one-time passwords with defined validity periods. Each password is generated for a specific time window and becomes invalid after expiration or single use, creating periodic authentication opportunities that reduce exposure time for credential transmission while enabling location-free printing operations

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS11704079B2Output system, information processing system, including circuitry to generate a character string to perform authentication for a user, and authentication method
Publication Date: 2023.07.18 RICOH CO LTD
  • US11704079B2 patent drawing
  • US11704079B2 patent drawing
  • US11704079B2 patent drawing

AI summary

An output system includes circuitry to generate information on a character string in response to an authentication request including user identification information transmitted from an output apparatus. The circuitry further transmits the information on the character string to an information processing device. In response to receiving the information on the character string and the user identification information from the output apparatus that has received the information on the character string and the user identification information from the information processing device, the circuitry further performs authentication for a user identified by the user identification information, based on the information on the character string and the user identification information, and transmits an authentication result to the output apparatus.