Single Sign-On Intermediary for Cloud Account Linking
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Users face difficulties in seamlessly signing into multiple cloud services using the single sign-on technique, especially when accounts from one cloud service are not registered in another, leading to unnecessary registration processes and lack of cooperation between cloud services.
Innovation Solution
An information processing apparatus is developed with modules for request reception, permission management, linking information management, and account management, enabling users to sign in to a second cloud service if their account is permitted to cooperate with another account, even if not directly registered, by utilizing a mapping table and permission tables to facilitate single sign-on across cloud services.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If single sign-on technique is used to enable seamless access to multiple cloud services, then user convenience and access speed are improved, but system complexity increases due to the need for account management modules, permission management modules, and linking information management modules
Solution Approach 1:
The patent introduces an information processing apparatus as an intermediary between multiple cloud services and user terminals. This apparatus includes dedicated modules (account management module, permission management module, linking information management module) that mediate authentication requests, manage account linkages, and control service permissions. The intermediary handles the complexity of cross-service authentication internally, allowing user terminals to access multiple cloud services seamlessly without implementing complex authentication logic themselves.
2Adaptability or versatility
If cloud services are integrated to allow account cooperation across services, then service versatility and functionality are improved, but security risks increase due to expanded permission scopes and potential unauthorized access
Solution Approach 1:
The patent implements fine-grained permission control where different cloud services are granted specific, localized permissions rather than blanket access. The permission management module stores and enforces permission information that specifies exactly which services can access which user accounts and under what conditions. This localized permission assignment allows versatile cross-service functionality while maintaining security by limiting each service's access scope to only what is necessary for its function.
Solution Approach 2:
The system establishes feedback loops through the linking information management module, which maintains mapping relationships between user accounts across different cloud services. When authentication or permission verification occurs, the system queries this linking information to verify authorized access. This feedback mechanism ensures that even as service versatility expands, security is maintained through continuous verification of account linkages and permission validity.
3Reliability
If account registration is required for each cloud service, then service security and account control are improved, but user time and operational steps increase due to multiple registration processes
Solution Approach 1:
The patent merges multiple account registration and authentication processes into a unified system. The linking information management module consolidates user account data across different cloud services, creating a unified view of user identities. When a user accesses a cloud service, the system checks the unified account linkage information rather than requiring separate registration at each service. This merging maintains account control and security through centralized verification while eliminating redundant registration steps, significantly reducing user time investment.
Data Source
AI summary
An information processing apparatus is provided. Assume that a user has signed into a first cloud service of operation source. In a case where the user signs in to a second cloud service of operation destination, and in a case where an account registered in the second cloud service is permitted to be cooperated with another account, the information processing apparatus allows the user to sign in to the second cloud service.


