Authentication Token Mediation for Image Forming Apparatus
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing image forming apparatuses lack a secure mechanism to authenticate users accessing jobs from external devices, leading to potential unauthorized changes or interruptions in printing processes, especially when errors occur and the authorized user is not present.
Innovation Solution
An image forming apparatus with an authentication system that requires both log-in authentication and job-specific authentication, using an authentication information input part, log-in authentication information input part, and an execution right judging part to ensure only authorized users can access and modify printing jobs, even when accessed from external devices.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If user authentication is required for direct access to the composite apparatus, then security is improved, but ease of operation deteriorates because users must input user ID and password each time
Solution Approach 1:
The patent introduces a host computer as an intermediary device that stores authentication information and issues authentication tokens. Instead of requiring direct authentication at the composite apparatus, the host computer mediates the authentication process by validating credentials and issuing tokens that grant access to specific functions, thereby improving ease of operation while maintaining security
2Speed
If authentication information is stored in the composite apparatus, then authentication speed is improved, but security deteriorates because the authentication information is exposed to the operation part
Solution Approach 1:
The patent extracts authentication information storage from the composite apparatus and relocates it to the host computer. The composite apparatus only stores authentication tokens issued by the host computer, not the actual authentication information. This extraction eliminates the security risk of exposing authentication information at the operation part while maintaining fast authentication through token validation
3Reliability
If the composite apparatus stops due to an error, then system reliability is improved by preventing further processing, but productivity deteriorates because the apparatus becomes unusable until the error is corrected
Solution Approach 1:
The patent segments the authentication function from the job processing function. The authentication part operates independently and can be accessed by any authenticated user, while job processing continues or can be resumed. This segmentation allows the system to maintain productivity even when errors occur, as users can authenticate and manage jobs separately from the main processing flow
4Ease of operation
If any logged-in user can modify jobs, then ease of operation is improved, but security deteriorates because unauthorized changes may be made
Solution Approach 1:
The patent applies local quality by assigning different access rights to different users based on their authentication status and job ownership. The authentication part allows any authenticated user to access, but job modification rights are locally restricted to the job owner or authorized users. This creates a differentiated access structure where authentication provides general access while job-specific authentication provides localized control, balancing ease of operation with security
Data Source
AI summary
An image forming apparatus includes an input part to input authentication information for authenticating a predetermined operation with respect to a registered printing job, an input part to input log-in authentication information for authenticating the predetermined operation from an operation part, an image forming part to form an image of the printing job, and a control part to request input of the authentication information for authenticating the predetermined operation with respect to a printing job that is being executed by the image forming part when the predetermined operation is made from the operation part in a logged in state, and authenticating the predetermined operation with respect to the printing job when authentication of the authentication information input by the input part is successful.


