Server-Mediated Authentication for Image Management Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing image management systems face challenges in enhancing information security when a portable terminal is used as an interface for an image processing apparatus, particularly in ensuring authentication consistency across devices and preventing unauthorized access.

Innovation Solution

An image management system that includes an image management apparatus, a portable information-processing terminal, and an image recipient apparatus, featuring an authentication-request transmitting unit, an information-displayed-on-apparatus transmitting unit, and an authentication processing unit, which generates ticket link information for user identification and device identification, ensuring secure access and storage of images.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a portable terminal is used as an operating unit of an image processing apparatus, then ease of operation is improved, but information security deteriorates due to authentication consistency requirements across multiple devices

Engineering Contradiction:
Improveease of operationVSAvoidinformation security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a server as an intermediary component that mediates authentication between the portable terminal and the image processing apparatus. The server issues authentication tickets to the terminal and verifies them with the image processing apparatus, ensuring secure authentication without requiring direct trust between the terminal and apparatus. This resolves the contradiction by maintaining ease of operation through portable terminal interface while ensuring information security through server-mediated authentication consistency.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If the image processing apparatus adds a function to transfer operational information to the portable terminal, then ease of operation is improved, but device complexity increases

Engineering Contradiction:
Improveease of operationVSAvoiddevice complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The server acts as an intermediary that handles the transfer of operational information between the portable terminal and the image processing apparatus. Instead of adding complex communication functions directly to the image processing apparatus, the server mediates this information transfer, thereby improving ease of operation while avoiding the increase of device complexity at the apparatus level.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If authentication results are made consistent among the image processing apparatus, server, and portable terminal, then information security is improved, but device complexity increases

Engineering Contradiction:
Improveinformation securityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The server serves as a central intermediary that manages and coordinates authentication results across all three devices. By consolidating authentication result consistency management at the server level, the system achieves improved information security without distributing the complexity across multiple devices. The server handles the coordination of authentication tickets and results, simplifying the overall system architecture while maintaining security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS9158928B2Image management system and image management apparatus
Publication Date: 2015.10.13 RICOH CO LTD
  • US9158928B2 patent drawing
  • US9158928B2 patent drawing
  • US9158928B2 patent drawing

AI summary

According to an aspect of the present invention, an image management apparatus includes: an authentication processing unit which authenticates access according to an authentication request; an information-displayed-on-apparatus receiving unit which receives displayed-on-apparatus information acquired based on information transmitted to and displayed on an image recipient apparatus in association with transmission of the authentication request; a ticket processing unit which generates ticket link information by generating ticket information for identification of the authentication and linking a user identifier of an authenticated user and a device identifier, which is acquired using the displayed-on-apparatus information received in association with the authentication, of the image recipient apparatus to the ticket information; and an image providing unit which, upon receiving an image request from the image recipient apparatus, acquires the device identifier of the image recipient apparatus and checks an authentication status of the user based on the ticket information linked to the device identifier.