Authorization Server for Centralized Consent Portal Routing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Users face a burden in managing consent across multiple authorization servers and consent portals, as the timing of consent requests for personal information access is unclear, requiring frequent checks across multiple platforms.
Innovation Solution
A data access control system that includes an authorization server capable of storing association relationships between users and consent portals, detecting target users for specific data conditions, obtaining consent intentions, and controlling access accordingly, thereby streamlining the consent process and reducing user burden.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If users perform user registration with multiple consent portals to manage consent for personal information access, then consent control capability is improved, but user operational burden increases
Solution Approach 1:
The patent introduces an authorization server as an intermediary between users and multiple consent portals. The authorization server stores association relationships between users and their respective consent portals, and automatically detects which consent portal a user should access based on their user ID. This mediator eliminates the need for users to manually manage multiple consent portal registrations, as the system automatically routes consent requests to the appropriate portal.
Solution Approach 2:
The authorization server performs multiple functions: it stores user-consent portal associations, detects target consent portals based on user ID, and manages access control across multiple platforms. By consolidating these functions in a single server, the system reduces the operational burden on users while maintaining comprehensive consent control capabilities across multiple consent portals.
2Loss of information
If users check multiple consent portals frequently to understand consent request timing, then consent awareness is improved, but time consumption increases
Solution Approach 1:
The authorization server provides feedback to users about consent request timing and status. When a consent request is made, the system notifies the user through the appropriate consent portal, and the authorization server tracks and manages the consent status. This feedback mechanism ensures users are informed about consent requests without needing to actively check multiple portals, reducing time consumption while maintaining consent awareness.
Solution Approach 2:
The authorization server pre-stores association relationships between users and consent portals, and pre-determines which consent portal should receive consent requests based on user ID. This preliminary setup eliminates the need for users to repeatedly check multiple portals to understand consent timing, as the system has already prepared the appropriate consent management pathway.
3Reliability
If the system implements access control across multiple authorization servers, then data security is improved, but system complexity increases
Solution Approach 1:
The patent merges the functions of multiple authorization servers into a single authorization server that manages consent associations for multiple users and consent portals. Instead of implementing separate access control systems at each authorization server, the system consolidates the association management functionality in one central server, reducing system complexity while maintaining data security through centralized control.
Solution Approach 2:
The authorization server acts as an intermediary that simplifies the interaction between multiple consent portals and users. By centralizing the association relationship storage and target consent portal detection in one server, the system reduces the complexity that would otherwise arise from coordinating multiple independent authorization servers, while still maintaining security through controlled access management.
Data Source
AI summary
A non-transitory computer-readable storage medium storing a program that causes a processor included in an authorization server to execute a process, the process includes storing an association relationship between a plurality of users who are owners of data, and a consent portal with which each of the plurality of users performs user registration, when consent of a user to access to data of a first condition is asked for by a client, detecting a target user who is an owner of data that matches the first condition, extracting a consent portal with which the target user performs user registration, from the association relationship, and obtaining an intention of consent or non-consent to access to the data, from the target user by using the extracted consent portal, and controlling an access by the client to data in the resource server, in accordance with the obtained intention.


