Proxy Authentication for Cloud Device Continuity

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In information processing systems where actual and virtual devices are linked in a cloud environment, successful authentication is required for operation, but user intervention is necessary when authentication fails due to private key compromise, disrupting service continuity.

Innovation Solution

An information processing system where a server manages proxy relationships between devices, allowing a proxy device to authenticate on behalf of a compromised device, ensuring seamless operation even if primary authentication fails, by using proxy relationship information to facilitate authentication through a proxy authentication request.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If authentication based on private key is used to ensure security, then reliability is improved, but if private key compromise is detected, service continuity is disrupted requiring user intervention

Engineering Contradiction:
Improveauthentication securityVSAvoidservice continuity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system performs preliminary actions by pre-registering proxy relationship information between devices before authentication failure occurs. When the first information processing apparatus detects private key compromise, it can immediately utilize the pre-established proxy relationship to authenticate through the second apparatus without requiring user intervention, thus maintaining service continuity while preserving security through the proxy authentication mechanism

Inventive Principle:
Principle #10Preliminary action

2Productivity

If proxy authentication is implemented to maintain service continuity, then productivity is improved, but device complexity increases due to additional authentication mechanisms

Engineering Contradiction:
Improveservice continuityVSAvoidauthentication mechanism complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The system introduces a second information processing apparatus as an intermediary that holds proxy relationship information. This intermediary enables the compromised first apparatus to authenticate through the second apparatus without requiring complex reconfiguration or user intervention. The proxy authentication mechanism adds minimal complexity by leveraging existing device relationships rather than implementing entirely new authentication protocols

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20250007912A1Information processing system, non-transitory computer readable medium, and method
Publication Date: 2025.01.02 FUJIFILM BUSINESS INNOVATION CORP
  • US20250007912A1 patent drawing
  • US20250007912A1 patent drawing
  • US20250007912A1 patent drawing

AI summary

An information processing system includes a processor included in a server that manages second information processing apparatuses, each of which, if authentication with a pair of information for proving that the second information processing apparatus and one of first information processing apparatuses form a pair is successfully completed, is operable in conjunction with the first information processing apparatus, which holds one of the pair of information, and holds another of the pair of the information, the processor configured to: cause the server to hold proxy relationship information in which proxy relationships between the first information processing apparatuses are set; send back, if, after the processor receives, from a first information processing apparatus that operates as a proxy apparatus in accordance with a proxy authentication request from another first information processing apparatus that operates as a proxy authentication request apparatus, a first authentication request that specifies one of a pair of information held by the proxy apparatus and a second authentication request for authenticating the proxy authentication request apparatus, authentication with the pair of information specified by the first authentication request is successfully completed and the proxy apparatus is servable as a proxy apparatus for the proxy authentication request apparatus according to the proxy relationship information, authentication information for authenticating the proxy authentication request apparatus; and authenticate, if the authentication information sent back to the proxy apparatus is added to communication data transmitted from the proxy authentication request apparatus, the proxy authentication request apparatus, even if a compromise of the one of the pair of information held by the proxy authentication request apparatus has been detected.