Unified Authentication Flow for Image Forming Apparatus Servers

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In existing user authentication methods for image forming apparatuses, managing periodic changes in authentication information across multiple devices is inconvenient, as each server (active directory and SMB) requires separate authentication, leading to cumbersome management and potential authentication failures.

Innovation Solution

A method where user authentication information successfully authenticated by a first server is used to authenticate the user with a second server for image data processing, allowing seamless authentication and data processing without the need for separate authentication information management across servers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If separate authentication is performed for each server (active directory and SMB), then each server can independently verify user credentials, but the management complexity increases and authentication failures may occur

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidauthentication management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines multiple authentication processes into a single integrated authentication flow. Instead of requiring separate authentication to active directory and SMB servers, the system performs one authentication action that serves both servers, thereby reducing management complexity while maintaining authentication reliability across the board.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The authentication mechanism is designed to be universal, where a single authentication credential set can be used across multiple server types (active directory and SMB). This multi-functional approach allows one authentication process to serve multiple purposes, eliminating the need for separate authentication management for each server.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If authentication information is periodically changed for each server, then security is maintained, but the convenience of continuous access is reduced due to separate management requirements

Engineering Contradiction:
ImprovesecurityVSAvoidaccess continuity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

By merging the authentication information management across servers, the system allows periodic changes to be made once rather than multiple times. The integrated authentication mechanism ensures that a single credential update reflects across all servers simultaneously, maintaining security while preserving continuous access convenience.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system implements feedback mechanisms that track authentication status across servers. When authentication information is updated, the system provides feedback to ensure the changes are propagated correctly, allowing administrators to maintain security through periodic updates without experiencing disruption to continuous access.

Inventive Principle:
Principle #23Feedback

3Reliability

If multiple authentication credentials are managed across servers, then each server can be secured independently, but the ease of managing authentication information decreases

Engineering Contradiction:
Improveserver securityVSAvoidauthentication information management
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent creates a universal authentication information structure that can be used across multiple server types. Instead of maintaining separate credential sets for active directory and SMB servers, the system uses a unified credential management approach that preserves the security benefits of independent server authentication while dramatically simplifying administration.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system introduces an intermediary authentication management layer that mediates between the user and multiple servers. This intermediary layer handles the complexity of credential management and propagation, allowing administrators to manage authentication information once while the intermediary ensures each server receives the appropriate credentials for secure operation.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8918852B2Method of authentication user using server and image forming apparatus using the method
Publication Date: 2014.12.23 HEWLETT PACKARD DEVELOPMENT COMPANY LP
  • US8918852B2 patent drawing
  • US8918852B2 patent drawing
  • US8918852B2 patent drawing

AI summary

A method of authenticating a user using a server and an image forming apparatus using the same, the method including: transmitting, from an image forming apparatus to a first server that functions as an authentication server, user authentication information; determining if the first server authenticates the user based on the user authentication information; and transmitting, to a second server that processes image data, the user authentication information if the first server authenticates the user, wherein the second server authenticates the user based on the transmitted user authentication information authenticated by the first server. Thus, the user of the image forming apparatus can be automatically authenticated by the second server by authenticating the user on the first server.