Token management device, method, storage medium and computer program product

The token management device receives and manages allowable conditions and issues conditional access tokens, which solves the problem that the second user cannot use the service to provide a server, and realizes the convenience of conditional access and utilization of the service of the second user.

CN111723392BActive Publication Date: 2025-05-13FUJIFILM BUSINESS INNOVATION CORP
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN201910833950.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2019-03-22
Filing Date
2019-09-04
Publication Date
2025-05-13
Estimated Expiration
2039-09-04

AI Technical Summary

Technical Problem

The prior art is difficult to implement services provided by the service providing server different from the first user with an access token and without an access token.

Method used

The token management device receives the allowable conditions of the first user and when the second user requests, a conditional access token is issued according to these allowable conditions, allowing the second user to utilize the service within the scope of the allowable conditions.

Benefits of technology

It is realized that the second user can conditionally utilize the services provided by the service provider server without having an access token, and improves the convenience and efficiency of the use of the service.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN111723392B_ABST
    Figure CN111723392B_ABST
Patent Text Reader

Abstract

A token management device, a storage medium and a token management method are provided, wherein the token management device comprises: a receiving unit, which receives a permission condition for allowing a second user who is different from a first user having an access token and does not have the access token from the first user to conditionally use the access token of the first user, wherein the token is used to access a service providing server that provides services; and an issuing unit, which issues a conditional access token that allows conditional use of the service within the scope of the permission condition to the second user when the second user requests conditional use of the access token of the first user and the request for conditional use satisfies the permission condition.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The invention relates to a token management device, a storage medium and a token management method. Background Art

[0002] Patent document 1 discloses a permission transfer system, which has a processing entrusting unit, a permission transfer unit and a management unit. The permission transfer system is characterized in that the processing entrusting unit has a generating unit, which generates a request including processing information representing the content of the processing in response to a processing entrustment from a user device operated by a user, the permission transfer unit has a sending unit, which receives the request generated by the generating unit and sends the request including the processing information to the management unit based on the request, the management unit has a judging unit, which receives the request sent by the sending unit and judges whether the processing can be executed in the management unit based on the processing information included in the request, and the permission transfer unit also has a determining unit, which determines to transfer the permission of the user of the management unit to the processing entrusting unit when the judging unit judges that the processing can be executed.

[0003] Patent Document 1: Japanese Patent Application Publication No. 2012-008958 Summary of the invention

[0004] The object of the present invention is to provide a token management device, storage medium and token management method that allow a second user who is different from a first user who has an access token of a service providing server and does not have an access token of the service providing server to conditionally use a service.

[0005] The token management device involved in method 1 comprises a receiving unit, which receives a permission condition for allowing a second user who is different from the first user and does not have the access token to conditionally use the access token of the first user from the first user, wherein the token is used to access a service providing server that provides services; and an issuing unit, which issues a conditional access token that allows the second user to use the service within the scope of the permission condition when the second user requests conditional use of the access token of the first user and the request for conditional use satisfies the permission condition.

[0006] The token management device involved in method 2 is a token management device involved in method 1, comprising: a storage unit for storing the conditional access token; and a control unit for controlling in the following manner when the second user requests conditional use of the service and receives the conditional access token, that is, when the received conditional access token is consistent with the conditional access token stored in the storage unit, requesting use of the service from the service providing server.

[0007] The token management device according to aspect 3 is the token management device according to aspect 2, wherein the control unit deletes the conditional access token from the storage unit when a predetermined deletion condition is satisfied.

[0008] A token management device according to aspect 4 is the token management device according to aspect 3, wherein the deletion condition is a case where the first user or the second user instructs to delete the conditional access token.

[0009] A token management device according to aspect 5 is the token management device according to aspect 3, wherein the deletion condition is a case where a predetermined period has passed since the issuance or last use of the conditional access token or the start or last use of the service.

[0010] A token management device according to aspect 6 is the token management device according to aspect 3, wherein the deletion condition is a case where a predetermined period of time has passed after an event related to the service occurs.

[0011] A token management device according to aspect 7 is the token management device according to aspect 6, wherein the control unit notifies the second user of the occurrence of the event.

[0012] The token management device according to mode 8 is the token management device according to mode 6 or mode 7, wherein the service providing server is a document management server that manages documents, and the occurrence of the event refers to the updating of the document.

[0013] A token management device according to aspect 9 is the token management device according to any one of aspects 1 to 8, wherein the control unit notifies the second user at a predetermined timing before the predetermined period elapses.

[0014] The token management device involved in method 10 is a token management device involved in any one of methods 1 to 9, wherein when the second user requests conditional use of the access token of the first user and the request for conditional use does not satisfy the permission condition, the issuing unit notifies the second user of the permission condition.

[0015] The token management device involved in method 11 is a token management device involved in any one of methods 1 to 9, wherein when the second user requests conditional use of the access token of the first user and the request for conditional use does not satisfy the permission condition, the issuing unit notifies the first user that use of the service requested by the second user is permitted.

[0016] In the token management device according to method 12, when the second user requests conditional use of the access token of the first user, the issuing unit requests the first user to log in, and when the first user logs in, issues the conditional access token.

[0017] A storage medium according to aspect 13 stores a token management program for causing a computer to function as each unit of the token management device according to any one of aspects 1 to 12.

[0018] The token management method involved in method 14 includes the following steps: a receiving step, in which a second user who is different from the first user having an access token and does not have the access token receives from the first user a permission condition for allowing conditional use of the access token of the first user, wherein the token is used to access a service providing server that provides services; and an issuing step, in which the second user requests conditional use of the access token of the first user, and when the request for conditional use satisfies the permission condition, a conditional access token is issued to the second user, allowing conditional use of the service within the scope of the permission condition.

[0019] Effects of the Invention

[0020] According to the first, thirteenth and fourteenth aspects, there is an effect that a second user who is different from a first user who has an access token to a service providing server and who does not have an access token to the service providing server can conditionally use the service.

[0021] According to the second aspect, there is an effect that, compared with a case where a conditional access token is not stored, it is not necessary to issue a conditional access token every time the second user requests conditional use of the access token of the first user.

[0022] According to the third aspect, there is an effect of being able to reduce the possibility of causing a security problem compared to a case where the conditional access token is not deleted from the storage unit.

[0023] According to the fourth aspect, there is an effect of being able to prevent the conditional access token from being deleted regardless of the intention of the first user or the second user.

[0024] According to the fifth aspect, there is an effect of saving the time and effort of the first user or the second user to instruct deletion of the conditional access token.

[0025] According to the sixth aspect, there is an effect of reducing the time required for the second user to request conditional use of the first user's access token again, compared to a case where the conditional access token is deleted before a predetermined period has passed after an event related to a service occurs.

[0026] According to the seventh aspect, there is an effect that the conditional access token can be prevented from being expired, compared to a case where the second user is not notified of the occurrence of the event.

[0027] According to the eighth aspect, there is an effect of preventing the conditional access token from being deleted before a predetermined period has passed after a document is updated.

[0028] According to the ninth aspect, there is an effect that, compared with a case where the second user is not notified before a predetermined period has elapsed, it is possible to suppress the conditional access token from being accidentally expired.

[0029] According to the tenth aspect, there is an effect that the second user can more easily understand the permission condition, compared with a case where no notification is given to the second user when the conditional use request does not satisfy the permission condition.

[0030] According to the eleventh aspect, there is an effect of being able to prompt the first user to permit the use of the service requested by the second user, compared to a case where no notification is given to the first user when the conditional use request does not satisfy the permission condition.

[0031] According to the twelfth aspect, there is an effect that the first user can easily understand that the second user requests to use the conditional access token, compared to a case where the first user is not requested to log in when the second user requests to conditionally use the first user's access token. BRIEF DESCRIPTION OF THE DRAWINGS

[0032] Embodiments of the present invention will be described in detail with reference to the following drawings.

[0033] Figure 1 is a structural diagram of a token management device system;

[0034] Figure 2 is a block diagram showing the electrical structure of a token management device;

[0035] Figure 3 is a block diagram showing the functional structure of a token management device;

[0036] Figure 4 is a flowchart showing an example of the processing flow of the token management program;

[0037] Figure 5 is a timing diagram showing an overview of the communication flow of each device;

[0038] Figure 6 is a diagram showing an example of an access token database;

[0039] Figure 7 This is a diagram showing an example of a setting screen for permission conditions;

[0040] Figure 8 is a diagram showing an example of a permission condition database;

[0041] Fig. 9 This is a diagram showing an example of an application screen for applying for conditional use of an access token.

[0042] Explanation of symbols

[0043] 1-token management system, 10-token management device, 12-controller, 14-communication unit, 16-storage unit, 16A-token management program, 16B-permission condition database, 16C-access token database, 20-service provider server, 30-first user terminal device, 40-second user terminal device, 50-receiving unit, 52-issuing unit, 54-control unit. DETAILED DESCRIPTION

[0044] Hereinafter, a mode for carrying out the present invention will be described in detail with reference to the drawings.

[0045] Figure 1 1 is a block diagram of a token management system 1. The token management system 1 is a structure in which a token management device 10, a first user terminal device 30, a second user terminal device 40, and a service providing server 20 are connected via a network N. In addition, the token management system 1 may include a plurality of token management devices 10, first user terminal devices 30, second user terminal devices 40, and service providing servers 20.

[0046] The token management device 10 manages access tokens of users who use services provided by the service providing server 20. Here, the access token is an identification code issued to a user who is given the authority to use the service.

[0047] The service providing server 20 has the function of an ID management device (IdP: Identity Provider) that manages user information such as user IDs and passwords of users who use services. The service providing server 20 performs user authentication on users who use services, and issues access tokens when authentication succeeds. In addition, the ID management device can also be set as an independent device.

[0048] The service providing server 20 provides services. Here, a service is an electronic process provided to a user, and examples thereof include, but are not limited to, processes related to document management, processes related to storage management, and processes related to sending and receiving emails. In this embodiment, as an example, a case where the service providing server 20 is a document management server is described.

[0049] The first user terminal device 30 is a terminal device used by a first user having an access token for accessing the service providing server 20 that provides services. The first user uses the service provided by the service providing server 20 using the first user terminal device 30 .

[0050] The second user terminal device 40 is a terminal device used by a second user who is different from the first user and does not have an access token.

[0051] As an example of the relationship between the first user and the second user, there can be cited the relationship between an employee of a development department of a product development (hereinafter referred to as an employee) and an employee of a client who commissions the product development (hereinafter referred to as a client). Furthermore, for example, when a document related to development such as a specification is managed in the service providing server 20 as a document management server, the employee has an access token and can access the specification, but the client does not have an access token and cannot access the specification. In this case, every time the client needs a specification, the employee accesses the service providing server 20 to obtain the specification and transfers it to the client, which is very complicated.

[0052] Therefore, the token management device 10 receives the permission condition for conditionally using the access token of the first user (staff) from the first user, and when the second user (delegator) requests conditionally using the access token of the first user, and the request for conditional use satisfies the permission condition, the token management device 10 issues a conditional access token that allows conditional use of the service within the scope of the permission condition to the second user. Thus, the second user can conditionally use the service even if he does not have the access token, for example, he can obtain the specification document. In addition, conditional use includes not only using part of the functions of the service, but also using all the functions of the service.

[0053] Figure 2 2 is a block diagram of the token management device 10. The token management device 10 is composed of a device including a general computer.

[0054] like Figure 2 As shown, the token management device 10 includes a controller 12. The controller 12 includes a CPU (Central Processing Unit) 12A, a ROM (Read Only Memory) 12B, a RAM (Random Access Memory) 12C, a non-volatile memory 12D, and an input / output interface (I / O) 12E. The CPU 12A, the ROM 12B, the RAM 12C, the non-volatile memory 12D, and the I / O 12E are connected to each other via a bus 12F.

[0055] Furthermore, the communication unit 14 and the storage unit 16 are connected to the I / O 12E.

[0056] The communication unit 14 is an interface for performing data communication with an external device.

[0057] The storage unit 16 is constituted by a nonvolatile storage device such as a hard disk, and stores a token management program 16A, a permission condition database (DB) 16B, an access token database (DB) 16C, etc. The CPU 12A reads and executes the token management program 16A stored in the storage unit 16 .

[0058] Next, the functional configuration of the CPU 12A when the token management device 10 executes the token management program 16A will be described.

[0059] like Figure 3 As shown, the CPU 12A functionally includes a receiving unit 50 , an issuing unit 52 , and a control unit 54 .

[0060] The receiving unit 50 receives, from the first user, a permission condition for permitting conditional use of the first user's access token for accessing the service providing server 20 providing a service, from the second user who is different from the first user and does not have an access token.

[0061] When the second user requests conditional use of the first user's access token and the request for conditional use satisfies the permission condition, the issuing unit 52 issues a conditional access token that permits conditional use of the service to the second user within the scope of the permission condition.

[0062] Furthermore, the issuing unit 52 has a function of notifying the second user of the permission condition when the second user requests conditional use of the access token of the first user and the request for conditional use does not satisfy the permission condition.

[0063] Furthermore, the issuing unit 52 has a function of notifying the first user that use of the service requested by the second user is permitted when the second user requests conditional use of the access token of the first user and the request for conditional use does not satisfy the permission condition.

[0064] Furthermore, the issuing unit 52 has a function of requesting the first user to log in when the second user requests conditional use of the first user's access token, and issuing a conditional access token when the first user logs in.

[0065] When the second user requests conditional use of the service and receives a conditional access token, the control unit 54 controls in such a manner that, when the received conditional access token matches the conditional access token stored in the storage unit 16 , the service providing server 20 is requested to use the service.

[0066] Furthermore, the control unit 54 has a function of deleting the conditional access token from the storage unit 16 when a predetermined deletion condition is satisfied.

[0067] Here, the deletion condition may be, for example, a case where the first user or the second user instructs to delete the conditional access token.

[0068] Furthermore, the deletion condition may be set to a case where a predetermined period has passed since the issuance or last use of the conditional access token or the start or last use of the service.

[0069] Furthermore, the deletion condition may be set to a case where a predetermined period of time has passed after an event related to the service occurs.

[0070] Furthermore, the control unit 54 has a function of notifying the second user of the occurrence of an event, for example, notifying the second user of the update of a document.

[0071] Furthermore, the control unit 54 has a function of notifying the second user at a predetermined timing before a predetermined period of time has passed.

[0072] Next, the function of the token management device 10 according to this embodiment will be described. Figure 2 As shown, the token management program 16A is stored in the storage unit 16. The token management program 16A is read and executed by the CPU 12A. Figure 4 In addition, the token management process is repeatedly executed at a predetermined time. Figure 4 The token management process shown. And, Figure 5 A timing diagram showing an overview of the communication flow between the devices is shown in FIG.

[0073] The access token used by the first user to access the service providing server 20 is issued by the service providing server 20 according to a predetermined access token issuance protocol and registered in the access token DB 16C. The access token issuance protocol may be, for example, OAuth2.0, but is not limited thereto.

[0074] like Figure 6 As shown, access token DB16C is a database that represents the correspondence between the user ID of the first user, the URL (Uniform Resource Locator) representing the connection destination of the service providing server 20, the access token issued to the first user, the user ID of the second user, and the conditional access token issued to the second user.

[0075] When the first user conditionally permits the second user to use the access token, the first user sets the permission conditions and transmits them to the token management device 10 .

[0076] Figure 7 FIG. 4 shows a setting screen G1 for allowing conditional use of the access token. Figure 7 As shown, the setting screen G1 includes: an input field N1 for inputting the second user allowed to use conditionally; a selection button B1 for selecting the second user allowed to use conditionally; an input field N2 for inputting the connection destination of the service provider server 20 allowed to use conditionally; a selection button B2 for selecting the operation allowed to use conditionally; an input field N3 for inputting the document name of the document allowed to use conditionally; a selection button B3 for selecting the document allowed to use conditionally; an input field N4 for inputting the start date and time of the permission period for conditional use; an input field N5 for inputting the end date and time of the permission period; and a confirmation button B4 for confirming the input content. In addition, Figure 7 The example of FIG. 1 shows a state where the pull-down menu PM is displayed by pressing the selection button B2. Figure 7 As shown, as an example, "reference document", "register document", "update document" and "delete document" can be selected.

[0077] The first user displays the Figure 7 Enter the required items in the setting screen G1 shown in FIG. 1 and press the confirmation button B4. Figure 5 As shown, the permission condition set by the first user is transmitted from the first user terminal device 30 to the token management device 10 .

[0078] In step S100, it is determined whether the permission condition is received from the first user terminal device 30. If the permission condition is received, the process proceeds to step S102, and if the permission condition is not received, the process proceeds to step S104.

[0079] In step S102, if Figure 5 As shown, the permission condition received in step S100 is registered in the permission condition DB 16B.

[0080] like Figure 8 As shown, the permission condition DB16B is a database that represents the correspondence between the user ID of the first user, the URL of the service providing server 20, the content of the operation allowed conditional use by the second user, the document name of the document allowed conditional use by the second user, and the permission period for conditional use of the document.

[0081] When the second user wants to conditionally use the access token of the first user, the second user sets application conditions and sends them to the token management device 10 .

[0082] Fig. 9 The application screen G2 for applying for conditional use of the access token is shown in FIG. Fig. 9As shown, the application screen G2 includes: an input field N11 for inputting the user ID of the first user having an access token for requesting conditional use; a selection button B11 for selecting the first user having an access token for requesting conditional use; an input field N12 for inputting the URL of the service providing server 20 for requesting conditional use; a selection button B12 for selecting the operation of requesting conditional use; an input field N13 for inputting the document name of the document for requesting conditional use; a selection button B13 for selecting the document for requesting conditional use; and a confirmation button B14 for confirming the input content.

[0083] The second user displays the Fig. 9 The user enters necessary information on the application screen G2 shown, and presses the confirmation button B14. As a result, the application conditions set by the second user are transmitted from the second user terminal device 40 to the token management device 10.

[0084] In step S104, it is determined whether the application condition is received from the second user terminal device 40. If the application condition is received, the process proceeds to step S106, and if the application condition is not received, the process proceeds to step S112.

[0085] In step S106, it is determined whether the application condition received in step S104 satisfies the permission condition. Specifically, it is determined whether there is a permission condition that satisfies the application condition received in step S104 among the permission conditions registered in the permission condition DB 16B with reference to the permission condition DB 16B stored in the storage unit 16. If there is a permission condition that satisfies the application condition received in step S104, the process proceeds to step S108, and if the application condition does not satisfy any permission condition, the process proceeds to step S110.

[0086] In step S108, a conditional access token is issued. Figure 5 As shown, a conditional access token is generated and sent to the second user terminal device 40. Then, the issued conditional access token is registered in the access token DB 16C.

[0087] Meanwhile, in step S110, the permission conditions required for using the first user's access token are sent to the second user terminal device 40 together with a message indicating that the first user's access token is not allowed to be used, thereby notifying the second user. Thus, the second user understands the permission conditions required for using the first user's access token.

[0088] Alternatively, the first user may be notified by transmitting a message requesting permission for use of the service requested by the second user to the first user terminal 30. This prompts the first user to set the permission condition.

[0089] Furthermore, when the second user requests conditional use of the access token of the first user, the first user may be requested to log in, and when the first user logs in, a conditional access token may be issued.

[0090] If a conditional access token is issued, the second user can obtain the document from the service providing server 20. Figure 5 As shown, the second user sends the document name of the document to be obtained and the issued conditional access token to the token management device 10 through the second user terminal device 40, and requests to obtain the document. In addition, the conditional access token can be input into the second user terminal device 40 by the second user, or the conditional access token can be stored in the internal memory of the second user terminal device 40 in advance and sent.

[0091] In step 112, it is determined whether a document acquisition request is received, that is, it is determined whether a document name and a conditional access token are received from the second user terminal device 40. If the document name and the conditional access token are received, the process proceeds to step S114, and if the document name and the conditional access token are not received, the process proceeds to step S120.

[0092] In step S114, it is determined whether the conditional access token received in step S112 is consistent with the conditional access token stored in the storage unit 16. Specifically, it is determined whether there is a conditional access token consistent with the conditional access token received in step S112 among the conditional access tokens logged in the access token DB 16C. If there is a conditional access token consistent with the conditional access token received in step S112, the process proceeds to step S116, and if there is no conditional access token consistent with the conditional access token received in step S112, the process proceeds to step S118.

[0093] In step S116, if Figure 5 As shown, the access token of the first user corresponding to the conditional access token received in step S112 is registered in the access token DB 16C and acquired, and sent to the service providing server 20 together with the document name, thereby requesting the service providing server 20 to use the service.

[0094] On the other hand, in step S118 , a message indicating that the conditional access token received in step S112 and the conditional access token stored in the storage unit 16 do not match is transmitted to the second user terminal device 40 , thereby notifying the second user.

[0095] In step S120, it is determined whether document data of the requested document is received from the service providing server 20. If the document data is received, the process proceeds to step S122, and if the document data is not received, the process proceeds to step S124.

[0096] In step S122, if Figure 5 As shown, the document data received in step S120 is transmitted to the second user terminal device 40. As a result, the second user can use the document within the range of the permission condition.

[0097] In step S124, it is determined whether a predetermined deletion condition is satisfied. And, when the deletion condition is satisfied, the routine proceeds to step S126, and when the deletion condition is not satisfied, the routine ends. Here, as a deletion condition, for example, is a case where the first user or the second user instructs to delete the conditional access token. And, the deletion condition can also be set to a case where a predetermined period has passed since the issuance of the conditional access token or the last use, or the use of the service or the last use. The predetermined period is set to a period (for example, 24 hours, etc.) during which security problems may arise if the conditional access token is still stored after a predetermined period has passed since the issuance of the conditional access token or the last use, or the use of the service or the last use. At this time, it can also be set to notify the second user at a predetermined timing before the predetermined period has passed. The predetermined timing is, for example, set to a timing that the second user can cope with to avoid the expiration of the conditional access token.

[0098] Furthermore, the deletion condition may also be set to a situation where a predetermined period has passed after an event related to the service occurs. The predetermined period is set to a period (e.g., 24 hours) during which security issues may arise if the conditional access token continues to be stored after a predetermined period has passed after the event occurs. At this time, it may also be set to notify the second user at a predetermined timing before the predetermined period has passed. The predetermined timing is, for example, set to a timing that the second user can cope with to avoid the conditional access token from expiring.

[0099] In addition, as an event, the document set in the application condition is updated. In addition, it can be set to notify the second user terminal device 40 of the occurrence of the event. For example, when the first user who is an employee updates a document such as a specification, if the specification is updated, the second user who is the client is automatically notified. Therefore, the second user does not need to confirm the update of the specification with the first user one by one, and can quickly confirm the updated specification. At this time, when the document is updated, it is necessary to notify the token management device 10 from the service provider server 20 that the document has been updated.

[0100] In step S126 , the conditional access token that satisfies the deletion condition is deleted from the access token DB 16C.

[0101] Thus, in this embodiment, even if the second user who is different from the first user who has the access token and does not have the access token satisfies the permission condition set by the first user for conditional use of the access token, a conditional access token for accessing the service providing server 20 that provides the service is issued to the second user. Therefore, the second user does not need to spend time obtaining the document through the first user every time the document is needed.

[0102] Although the embodiments are described above, the technical scope of the present invention is not limited to the above embodiments. Various changes or improvements can be made to the above embodiments without departing from the spirit of the invention, and such changes or improvements are also included in the technical scope of the present invention.

[0103] Furthermore, the above-mentioned embodiments do not limit the invention involved in the claims, and all combinations of the features described in the embodiments are not necessarily necessary for the solution of the invention. The above-mentioned embodiments include inventions at various stages, and various inventions can be extracted by combining the disclosed multiple constituent elements. Even if some constituent elements are deleted from all the constituent elements shown in the embodiments, as long as the effect can be obtained, the structure in which some constituent elements are deleted can be extracted as an invention.

[0104] Furthermore, in the above embodiment, the token management program is pre-installed in the storage unit 16, but the present invention is not limited thereto. For example, the token management program may be provided in a storage medium such as a CD-ROM (Compact Disc Read Only Memory) or provided via a network.

[0105] Furthermore, in the above embodiment, the token management process is implemented by executing a program and using a computer and a software structure, but the present invention is not limited to this. For example, the token management process may be implemented by a hardware structure or a combination of a hardware structure and a software structure.

[0106] In addition, the structure of the token management device 10 described in the above embodiment (refer to Figure 2 . ) is an example, and it is natural that unnecessary parts can be deleted or new parts can be added without departing from the scope of the present invention.

[0107] Furthermore, the processing flow of the token management program 16A described in the above embodiment (see Figure 4 ) is also an example. It is natural that unnecessary steps can be deleted or new steps can be added or the processing order can be replaced without departing from the scope of the present invention.

[0108] The above-mentioned embodiments of the present invention are provided for the purpose of illustration and description. In addition, the embodiments of the present invention do not fully and exhaustively include the present invention, and do not limit the present invention to the disclosed methods. Obviously, various modifications and changes are self-evident to those skilled in the art to which the present invention belongs. The present embodiment is selected and described in order to most easily understand the principles of the present invention and its application. Thus, other technicians in the art can understand the present invention through various variations optimized for specific uses assumed to be various embodiments. The scope of the present invention is defined by the above claims and their equivalents.

Claims

1. A token management device, comprising: a receiving unit that receives, from a first user who is different from a first user having an access token and does not have the access token, a permission condition for allowing conditional use of the access token of the first user, and receives, from the second user, a request for conditional use of the access token of the first user, the token being used to access a service providing server that provides a service; an issuing unit, which, when the request for conditional use satisfies the permission condition, issues a conditional access token for permitting conditional use of the service to the second user within the scope of the permission condition; A storage unit, storing the conditional access token; and The control unit controls, when the second user requests conditional use of the service and receives a conditional access token, to request use of the service from the service providing server when the received conditional access token matches the conditional access token stored in the storage unit, wherein: When a predetermined deletion condition is satisfied, the control unit deletes the conditional access token from the storage unit, wherein: The deletion condition is a situation where a predetermined period of time has passed after an event related to the service occurs, wherein: The service providing server is a document management server that manages documents, and the occurrence of the event refers to the document being updated.

2. The token management device according to claim 1, wherein: The deletion condition is a case where the first user or the second user instructs to delete the conditional access token.

3. The token management device according to claim 1, wherein: The deletion condition is a case where the predetermined period has elapsed since the issuance or last use of the conditional access token or the start of use or last use of the service.

4. The token management device according to claim 1, wherein: The control unit notifies the second user of the occurrence of the event.

5. The token management device according to claim 3 or 4, wherein: The control unit notifies the second user at a predetermined timing before the predetermined period elapses.

6. The token management device according to any one of claims 1 to 4, wherein: When the second user requests conditional use of the access token of the first user and the request for conditional use does not satisfy the permission condition, the issuing unit notifies the second user of the permission condition.

7. The token management device according to any one of claims 1 to 4, wherein: When the second user requests conditional use of the access token of the first user and the request for conditional use does not satisfy the permission condition, the issuing unit notifies the first user that use of the service requested by the second user is permitted.

8. The token management device according to claim 1, wherein: When the second user requests conditional use of the access token of the first user, the issuing unit requests the first user to log in, and when the first user logs in, issues the conditional access token. 9 . A storage medium storing a token management program for causing a computer to function as each unit of the token management device according to claim 1 .

10. A token management method comprising the following steps: a receiving step of receiving, for a second user who is different from the first user having the access token and does not have the access token, from the first user a permission condition for allowing conditional use of the access token of the first user, and receiving, from the second user, a request for conditional use of the access token of the first user, the token being used to access a service providing server that provides a service; and issuing a conditional access token for permitting conditional use of the service to the second user within the scope of the permission condition when the conditional use request satisfies the permission condition; A storing step, storing the conditional access token; and A control step, in which, when the second user requests conditional use of the service and receives a conditional access token, control is performed in the following manner, that is, when the received conditional access token is consistent with the stored conditional access token, the service providing server is requested to use the service, wherein: When a predetermined deletion condition is met, the stored conditional access token is deleted, wherein: The deletion condition is a situation where a predetermined period of time has passed after an event related to the service occurs, wherein: The service providing server is a document management server that manages documents, and the occurrence of the event refers to the document being updated.

11. A computer program product that causes a computer to function as each unit of the token management device according to any one of claims 1 to 8.

Citation Information

Patent Citations

  • Authority transfer system, authority transfer method, information processor and program

    JP2012008958A

  • Method for managing access to protected resources and delegating authority in a computer network

    CN103039050A