Secure Scan Data Storage via Management Server Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data output systems face challenges in securely storing scan data directly on a user's computer while ensuring security, particularly when sharing files over networks, as they often require additional user effort and may compromise security.

Innovation Solution

An information processing system that allows direct storage of data output from a data output apparatus to a user's computer, utilizing a management server and authentication server to manage user authentication and folder settings, ensuring secure storage by verifying user authentication information and connecting the data output apparatus with the client PC securely.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If scan data is transmitted and saved in a shared folder on the network, then the additional work of moving scan data to the target folder is omitted, but it becomes difficult to secure security

Engineering Contradiction:
Improveease of operationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a management server as an intermediary between the scanner and the user's computer. The management server receives scan data from the scanner, authenticates the user, and then transfers the data to the appropriate location on the user's computer. This mediator approach allows automated data transfer without requiring the user to manually move files, while simultaneously maintaining security through centralized authentication and controlled access.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system segments the data transfer process into distinct functional components: data collection by the scanner, authentication by the management server, and data delivery to the user's computer. This segmentation allows each component to perform its specific function securely, with the management server acting as a secure gateway that verifies user identity before allowing data access, thus resolving the contradiction between automated operation and security.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If a file server or user's computer folder is shared on the network for storing scan data, then direct storage is enabled, but security is compromised

Engineering Contradiction:
ImproveadaptabilityVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The management server serves as a secure intermediary that mediates between the networked scanner and the user's computer. Instead of directly sharing folders on the user's computer or file server, the management server receives scan data, verifies user authentication credentials, and then securely transfers data to the appropriate location. This intermediary layer enables direct storage functionality while preventing unauthorized access and maintaining security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements self-service authentication where the management server automatically verifies user credentials and determines appropriate data storage locations without requiring manual user intervention. The server autonomously manages the security verification process, checking user identity and permissions before allowing data transfer, thus enabling adaptable direct storage while maintaining security through automated authentication.

Inventive Principle:
Principle #25Self-service

3Quantity of substance

If scan data is attached to e-mail and transmitted to a mail box, then data can be transferred, but the user requires additional work to acquire and move the data to a target folder

Engineering Contradiction:
Improvedata transfer capabilityVSAvoiduser effort
Core Design Contradiction:
Quantity of substanceVSLoss of time

Solution Approach 1:

The management server performs preliminary actions by automatically receiving scan data from the scanner, authenticating the user, and directly transferring the data to the user's computer in the appropriate folder location. This preliminary automated processing eliminates the need for users to manually acquire data from email and move it to target folders, thus reducing user effort and time loss while maintaining data transfer capability.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements self-service automated data transfer where the management server autonomously handles the entire data transfer process from scanner to user's computer without requiring user intervention for file movement. The server automatically authenticates users, determines appropriate storage locations, and completes the transfer, thereby eliminating the additional user work and time loss associated with manual file management while preserving data transfer functionality.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP3416362B1Data storage management in information processing system
Publication Date: 2023.08.09 RICOH CO LTD
  • EP3416362B1 patent drawingFigure 1~2
  • EP3416362B1 patent drawingFigure 3~4
  • EP3416362B1 patent drawingFigure 5

AI summary

An information system (1) includes an information processing apparatus (10) and a data output apparatus (20). The information processing apparatus (10) includes a receiver (120), a second authentication processor (121) and a transmitter (121,123). The data output apparatus (20) includes a first authentication processor (210), a requester (223), and a data transmitter (221). The first authentication processor (210) requests an authentication according to first authentication information input to the data output apparatus (20). The requester (223) transmits, to the information processing apparatus (10), the first authentication information authenticated and a transmission request of information that indicates one or more storage locations to store data. The receiver (120) receives, from the data output apparatus (20), the first authentication information and the transmission request. The second authentication processor (121) requests an authentication according to second authentication information input to the information processing apparatus (10). The transmitter (121,123) transmits information indicating the storage locations based on a determination that the first authentication information and the second authentication information authenticated have a predetermined relationship. The data transmitter (221) transmits the data output from the data output apparatus (20) to the storage locations.