Authentication Token Mediation for Image Forming Apparatus

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing image forming apparatuses lack a secure mechanism to authenticate users accessing jobs from external devices, leading to potential unauthorized changes or interruptions in printing processes, especially when errors occur and the authorized user is not present.

Innovation Solution

An image forming apparatus with an authentication system that requires both log-in authentication and job-specific authentication, using an authentication information input part, log-in authentication information input part, and an execution right judging part to ensure only authorized users can access and modify printing jobs, even when accessed from external devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If user authentication is required for direct access to the composite apparatus, then security is improved, but ease of operation deteriorates because users must input user ID and password each time

Engineering Contradiction:
ImprovesecurityVSAvoidease of operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces a host computer as an intermediary device that stores authentication information and issues authentication tokens. Instead of requiring direct authentication at the composite apparatus, the host computer mediates the authentication process by validating credentials and issuing tokens that grant access to specific functions, thereby improving ease of operation while maintaining security

Inventive Principle:
Principle #24Intermediary (Mediator)

2Speed

If authentication information is stored in the composite apparatus, then authentication speed is improved, but security deteriorates because the authentication information is exposed to the operation part

Engineering Contradiction:
Improveauthentication speedVSAvoidsecurity
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The patent extracts authentication information storage from the composite apparatus and relocates it to the host computer. The composite apparatus only stores authentication tokens issued by the host computer, not the actual authentication information. This extraction eliminates the security risk of exposing authentication information at the operation part while maintaining fast authentication through token validation

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If the composite apparatus stops due to an error, then system reliability is improved by preventing further processing, but productivity deteriorates because the apparatus becomes unusable until the error is corrected

Engineering Contradiction:
Improvesystem reliabilityVSAvoidproductivity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent segments the authentication function from the job processing function. The authentication part operates independently and can be accessed by any authenticated user, while job processing continues or can be resumed. This segmentation allows the system to maintain productivity even when errors occur, as users can authenticate and manage jobs separately from the main processing flow

Inventive Principle:
Principle #1Segmentation

4Ease of operation

If any logged-in user can modify jobs, then ease of operation is improved, but security deteriorates because unauthorized changes may be made

Engineering Contradiction:
Improveease of operationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent applies local quality by assigning different access rights to different users based on their authentication status and job ownership. The authentication part allows any authenticated user to access, but job modification rights are locally restricted to the job owner or authorized users. This creates a differentiated access structure where authentication provides general access while job-specific authentication provides localized control, balancing ease of operation with security

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS7657753B2Image forming apparatus, information processing apparatus, information processing system, authentication method and computer-readable storage medium
Publication Date: 2010.02.02 RICOH CO LTD
  • US7657753B2 patent drawing
  • US7657753B2 patent drawing
  • US7657753B2 patent drawing

AI summary

An image forming apparatus includes an input part to input authentication information for authenticating a predetermined operation with respect to a registered printing job, an input part to input log-in authentication information for authenticating the predetermined operation from an operation part, an image forming part to form an image of the printing job, and a control part to request input of the authentication information for authenticating the predetermined operation with respect to a printing job that is being executed by the image forming part when the predetermined operation is made from the operation part in a logged in state, and authenticating the predetermined operation with respect to the printing job when authentication of the authentication information input by the input part is successful.