Printing Apparatus Multi-Factor Authentication Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

There is a security risk in printing apparatuses where multi-factor authentication settings can be changed from one authentication service to another, potentially deactivating multi-factor authentication, allowing unauthorized access without performing the required authentication factors.

Innovation Solution

The printing apparatus includes separate authentication units for local and remote access, ensuring that multi-factor authentication is not deactivated from remote access if it is activated for local access, and vice versa, thereby preventing unauthorized login and reducing security risks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If multi-factor authentication settings can be changed from one authentication service to another, then ease of operation is improved, but security is worsened

Engineering Contradiction:
Improveability to change authentication settingsVSAvoidauthentication security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the authentication system into separate authentication services (local access service and remote access service), each with independent multi-factor authentication settings. This allows the system to manage security settings for different access methods separately, preventing a change in one service from affecting another, thus resolving the contradiction between ease of operation and security.

Inventive Principle:
Principle #1Segmentation

2Ease of operation

If multi-factor authentication is deactivated for remote access, then ease of operation is improved, but security is worsened

Engineering Contradiction:
Improveremote access convenienceVSAvoidunauthorized access risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent implements preliminary anti-action by detecting when multi-factor authentication is deactivated for one access service and proactively preventing deactivation for other services. The control unit monitors authentication setting changes and automatically maintains multi-factor authentication status across different services, countering potential security compromises before they can occur.

Inventive Principle:
Principle #9Preliminary anti-action

3Reliability

If separate multi-factor authentication settings are maintained for different access methods, then security is improved, but device complexity is worsened

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies universality by implementing a centralized control unit that manages multiple authentication services with a unified security policy. The control unit provides multi-functional capabilities by monitoring and coordinating authentication settings across different access services, allowing the system to maintain separate settings while being managed through a single universal control mechanism, thus reducing perceived complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11989313B2Printing apparatus, method for controlling printing apparatus, and storage medium
Publication Date: 2024.05.21 CANON KK
  • US11989313B2 patent drawing
  • US11989313B2 patent drawing
  • US11989313B2 patent drawing

AI summary

An image forming apparatus including a function including at least a print function includes a first authentication unit configured to perform authentication processing on local access to the image forming apparatus, a second authentication unit configured to perform authentication processing on remote access to the image forming apparatus, and a reception unit configured to receive separately a setting to activate multi-factor authentication processing including a plurality of authentication factors in the authentication of the local access and a setting to activate multi-factor authentication processing including a plurality of authentication factors in the authentication of the remote access. In a case where the multi-factor authentication processing for the local access is activated and the multi-factor authentication processing for the remote access is not activated, the activated multi-factor authentication processing for the local access is controlled not to be deactivated from the authenticated remote access.