Server Apparatus Segmentation for Unauthorized Service Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing server apparatuses fail to prevent unauthorized use of services by third parties when electronic appliances storing user authentication information are transferred, as the third party can access services using the original user's authentication details.

Innovation Solution

A server apparatus with a reception unit for user and appliance identification, a storage unit for use permission/prohibition information, an acceptance unit for service type information, and a determination unit to assess permission/prohibition settings, ensuring only authorized users can access specific services on connected electronic appliances.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If electronic appliances store user authentication information locally, then service access convenience is improved, but security against unauthorized use by third parties deteriorates

Engineering Contradiction:
Improveservice access convenienceVSAvoidsecurity against unauthorized use
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The authentication system is segmented into two parts: authentication information storage remains on the electronic appliance for convenience, while authorization management is separated and controlled by the server apparatus. This allows the appliance to quickly access services using stored credentials while the server validates and controls actual service permission, preventing unauthorized third-party access.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The server apparatus acts as an intermediary between the electronic appliance and the services. The appliance stores authentication information and can quickly access services, but the server mediates by verifying authorization requests and controlling service permission based on registered relationships between users and appliances, thus maintaining security without compromising convenience.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Speed

If authentication information is stored on electronic appliances, then service access speed is improved, but control over service permission after device transfer deteriorates

Engineering Contradiction:
Improveservice access speedVSAvoidcontrol over service permission
Core Design Contradiction:
SpeedVSAdaptability or versatility

Solution Approach 1:

The system performs preliminary registration of the relationship between user identification information and appliance identification information with the server apparatus before service access. This preliminary action enables fast service access using stored credentials while ensuring the server has advance knowledge of authorized combinations, allowing it to control service permission even after device transfer.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The server apparatus provides feedback control by verifying each service access request against the registered user-appliance relationships. When an appliance attempts to access a service, the server checks whether the combination of user ID and appliance ID is authorized, and can dynamically control permission based on this feedback, maintaining adaptability despite fast local access.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS8561156B2Server apparatus, and control method and computer-readable storage medium therefor
Publication Date: 2013.10.15 CANON KK
  • US8561156B2 patent drawing
  • US8561156B2 patent drawing
  • US8561156B2 patent drawing

AI summary

A server apparatus capable of preventing unauthorized use of services by a third party through an electronic appliance that stores information used for user authentication by the server apparatus. The server apparatus receives, from an information processing apparatus, pieces of user identification information, pieces of appliance identification information, and pieces of use permission/prohibition information representing on a per service type basis whether uses of services are permitted or prohibited, and stores them so as to be associated with one another. When determining based on use permission/prohibition information, which is associated with a combination of user identification information and appliance identification information that are accepted from an electronic appliance, that use of a service represented by service type information accepted from the electronic appliance is permitted, the server apparatus transmits screen information for use of the service to the electronic appliance.