Pluggable Authentication Module for Multifunction Peripheral Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Multifunction peripherals (MFPs) from different manufacturers often lack a common authentication protocol, making it difficult to manage user access and security across a networked fleet of devices with varying capabilities.

Innovation Solution

The implementation of a Pluggable Authentication Module (PAM) that integrates multiple low-level authentication schemes into a high-level application programming interface, allowing MFPs to utilize external authentication servers for secure user access, even if the devices do not natively support Multi-Function Device Services (MDS) or application authentication modes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a common authentication protocol is used across all MFPs, then user access management becomes standardized and simplified, but devices from manufacturers that do not support the protocol cannot be integrated

Engineering Contradiction:
Improvecompatibility across different MFP manufacturersVSAvoidauthentication protocol implementation
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary authentication mechanism that translates between different authentication protocols. The system captures authentication credentials from various MFP manufacturers through their native protocols and translates them into a unified authentication framework, enabling standardized access management without requiring modification to the diverse device fleet

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The authentication system is designed to support multiple authentication protocols simultaneously, making it universal in its ability to handle different MFP manufacturers. The system can authenticate users from devices supporting different protocols (such as Active Directory, LDAP, or manufacturer-specific protocols) through a single unified interface

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If external authentication servers are implemented, then centralized security management is achieved, but devices without native support for authentication protocols cannot connect

Engineering Contradiction:
Improvesecurity managementVSAvoiddevice compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system acts as an intermediary layer between external authentication servers and MFPs with varying protocol support. It captures authentication requests from the MFP, translates them into the appropriate protocol for the external server, and relays the authentication result back, thereby enabling centralized security management while maintaining broad device compatibility

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system dynamically changes authentication parameters based on the capabilities of the connecting MFP. It detects which authentication protocols are available on the device and adjusts the authentication method accordingly, allowing the same external authentication server to work with devices having different protocol support

Inventive Principle:
Principle #35Parameter changes

3Ease of manufacture

If device-specific authentication protocols are used, then each device maintains its native security capabilities, but network-wide access control becomes fragmented and difficult to manage

Engineering Contradiction:
Improvedevice independenceVSAvoidnetwork access management
Core Design Contradiction:
Ease of manufactureVSEase of operation

Solution Approach 1:

The authentication system is segmented into independent components: device-specific protocol handlers that maintain native security capabilities and a central coordination layer that provides network-wide access control. Each MFP can use its native protocol while the central system coordinates authentication across the entire network, preventing fragmentation

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS12001736B1System and method for providing alternative authentication modes in multifunction peripherals
Publication Date: 2024.06.04 TOSHIBA TEC KK
  • US12001736B1 patent drawing
  • US12001736B1 patent drawing
  • US12001736B1 patent drawing

AI summary

A system and method for providing alternative authentication modes in multifunction peripherals includes supplying mobile device management and application authentication to multifunction peripherals without such capabilities. A pluggable authorization module is installed on an incompatible multifunction peripheral by providing a user login on a devices idle screen with an login URL. A user's login credentials are verified by an authentication server that returns an associated username and access permissions once verified. This information is used by the pluggable authorization module to generate a temporary multi-function device services user supplied with the retrieved access permissions. The user can then use the multifunction device services via the temporary user. The temporary user is deleted once the user logs out.