Authorization Server for Centralized Consent Portal Routing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users face a burden in managing consent across multiple authorization servers and consent portals, as the timing of consent requests for personal information access is unclear, requiring frequent checks across multiple platforms.

Innovation Solution

A data access control system that includes an authorization server capable of storing association relationships between users and consent portals, detecting target users for specific data conditions, obtaining consent intentions, and controlling access accordingly, thereby streamlining the consent process and reducing user burden.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If users perform user registration with multiple consent portals to manage consent for personal information access, then consent control capability is improved, but user operational burden increases

Engineering Contradiction:
Improveconsent control capabilityVSAvoiduser operational burden
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces an authorization server as an intermediary between users and multiple consent portals. The authorization server stores association relationships between users and their respective consent portals, and automatically detects which consent portal a user should access based on their user ID. This mediator eliminates the need for users to manually manage multiple consent portal registrations, as the system automatically routes consent requests to the appropriate portal.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The authorization server performs multiple functions: it stores user-consent portal associations, detects target consent portals based on user ID, and manages access control across multiple platforms. By consolidating these functions in a single server, the system reduces the operational burden on users while maintaining comprehensive consent control capabilities across multiple consent portals.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Loss of information

If users check multiple consent portals frequently to understand consent request timing, then consent awareness is improved, but time consumption increases

Engineering Contradiction:
Improveconsent awarenessVSAvoidtime consumption
Core Design Contradiction:
Loss of informationVSLoss of time

Solution Approach 1:

The authorization server provides feedback to users about consent request timing and status. When a consent request is made, the system notifies the user through the appropriate consent portal, and the authorization server tracks and manages the consent status. This feedback mechanism ensures users are informed about consent requests without needing to actively check multiple portals, reducing time consumption while maintaining consent awareness.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The authorization server pre-stores association relationships between users and consent portals, and pre-determines which consent portal should receive consent requests based on user ID. This preliminary setup eliminates the need for users to repeatedly check multiple portals to understand consent timing, as the system has already prepared the appropriate consent management pathway.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If the system implements access control across multiple authorization servers, then data security is improved, but system complexity increases

Engineering Contradiction:
Improvedata securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the functions of multiple authorization servers into a single authorization server that manages consent associations for multiple users and consent portals. Instead of implementing separate access control systems at each authorization server, the system consolidates the association management functionality in one central server, reducing system complexity while maintaining data security through centralized control.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The authorization server acts as an intermediary that simplifies the interaction between multiple consent portals and users. By centralizing the association relationship storage and target consent portal detection in one server, the system reduces the complexity that would otherwise arise from coordinating multiple independent authorization servers, while still maintaining security through controlled access management.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11843603B2Authorization server, consent portal, resource server and user registration
Publication Date: 2023.12.12 FUJITSU LTD
  • US11843603B2 patent drawing
  • US11843603B2 patent drawing
  • US11843603B2 patent drawing

AI summary

A non-transitory computer-readable storage medium storing a program that causes a processor included in an authorization server to execute a process, the process includes storing an association relationship between a plurality of users who are owners of data, and a consent portal with which each of the plurality of users performs user registration, when consent of a user to access to data of a first condition is asked for by a client, detecting a target user who is an owner of data that matches the first condition, extracting a consent portal with which the target user performs user registration, from the association relationship, and obtaining an intention of consent or non-consent to access to the data, from the target user by using the extracted consent portal, and controlling an access by the client to data in the resource server, in accordance with the obtained intention.