Single Sign-On Intermediary for Cloud Account Linking

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users face difficulties in seamlessly signing into multiple cloud services using the single sign-on technique, especially when accounts from one cloud service are not registered in another, leading to unnecessary registration processes and lack of cooperation between cloud services.

Innovation Solution

An information processing apparatus is developed with modules for request reception, permission management, linking information management, and account management, enabling users to sign in to a second cloud service if their account is permitted to cooperate with another account, even if not directly registered, by utilizing a mapping table and permission tables to facilitate single sign-on across cloud services.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If single sign-on technique is used to enable seamless access to multiple cloud services, then user convenience and access speed are improved, but system complexity increases due to the need for account management modules, permission management modules, and linking information management modules

Engineering Contradiction:
Improveuser convenienceVSAvoidsystem complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent introduces an information processing apparatus as an intermediary between multiple cloud services and user terminals. This apparatus includes dedicated modules (account management module, permission management module, linking information management module) that mediate authentication requests, manage account linkages, and control service permissions. The intermediary handles the complexity of cross-service authentication internally, allowing user terminals to access multiple cloud services seamlessly without implementing complex authentication logic themselves.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If cloud services are integrated to allow account cooperation across services, then service versatility and functionality are improved, but security risks increase due to expanded permission scopes and potential unauthorized access

Engineering Contradiction:
Improveservice versatilityVSAvoidsecurity risks
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements fine-grained permission control where different cloud services are granted specific, localized permissions rather than blanket access. The permission management module stores and enforces permission information that specifies exactly which services can access which user accounts and under what conditions. This localized permission assignment allows versatile cross-service functionality while maintaining security by limiting each service's access scope to only what is necessary for its function.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system establishes feedback loops through the linking information management module, which maintains mapping relationships between user accounts across different cloud services. When authentication or permission verification occurs, the system queries this linking information to verify authorized access. This feedback mechanism ensures that even as service versatility expands, security is maintained through continuous verification of account linkages and permission validity.

Inventive Principle:
Principle #23Feedback

3Reliability

If account registration is required for each cloud service, then service security and account control are improved, but user time and operational steps increase due to multiple registration processes

Engineering Contradiction:
Improveaccount controlVSAvoiduser time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent merges multiple account registration and authentication processes into a unified system. The linking information management module consolidates user account data across different cloud services, creating a unified view of user identities. When a user accesses a cloud service, the system checks the unified account linkage information rather than requiring separate registration at each service. This merging maintains account control and security through centralized verification while eliminating redundant registration steps, significantly reducing user time investment.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS10708254B2Information processing apparatus and non-transitory computer readable medium storing information processing program for single sign-on
Publication Date: 2020.07.07 FUJIFILM BUSINESS INNOVATION CORP
  • US10708254B2 patent drawing
  • US10708254B2 patent drawing
  • US10708254B2 patent drawing

AI summary

An information processing apparatus is provided. Assume that a user has signed into a first cloud service of operation source. In a case where the user signs in to a second cloud service of operation destination, and in a case where an account registered in the second cloud service is permitted to be cooperated with another account, the information processing apparatus allows the user to sign in to the second cloud service.