Cross-Server Role Assignment via Relationship Mapping

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional technologies cannot accurately determine and assign appropriate roles to users authenticated by different servers, leading to inconsistent service access despite identical roles, as the reliability of user authentication varies across servers.

Innovation Solution

A method and apparatus that determine an appropriate role for a user authenticated by another apparatus by referencing relationship information and role assignment policies between servers, enabling tailored service provision based on the server of authentication and assigned roles.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If users with identical roles are authenticated by different servers, then the same role is assigned to all users, but the service access and reliability become inconsistent across servers

Engineering Contradiction:
Improveservice access controlVSAvoidauthentication reliability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent applies local quality by assigning different service access levels to users based on their specific authentication server and role combination. Instead of uniform role assignment, the system tailors service permissions locally according to the server-Role-user triad, ensuring that users authenticated by different servers receive appropriately differentiated access even with identical role titles.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system dynamically determines service access by considering multiple variables: the authentication server identity, the user's role at that server, and the relationship between servers. This dynamic approach allows the same user role to grant different service levels depending on which server performed authentication, thereby adapting service reliability to the specific authentication context.

Inventive Principle:
Principle #15Dynamics

2Ease of operation

If role assignment is simplified to treat all users with the same role equally, then ease of operation improves, but the precision of access control deteriorates

Engineering Contradiction:
Improverole assignment simplicityVSAvoidaccess control precision
Core Design Contradiction:
Ease of operationVSMeasurement precision

Solution Approach 1:

The patent changes the parameters used for role assignment from a single role identifier to a composite key including authentication server ID, user role, and service target. This parameter expansion maintains operational simplicity by using existing role concepts while achieving precise access control through the combination of multiple parameters that capture the nuanced relationship between users, servers, and services.

Inventive Principle:
Principle #35Parameter changes

3Device complexity

If each server independently manages user authentication, then device complexity is reduced, but the ability to provide differentiated services across servers deteriorates

Engineering Contradiction:
Improveauthentication system complexityVSAvoidcross-server service differentiation
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The patent implements universality by creating a role assignment mechanism that works across multiple servers with a unified approach. Each server maintains independent authentication capability, but the role assignment system universally applies the server-role-service mapping logic across all servers, enabling differentiated service provision without requiring complex inter-server authentication coordination.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP2634721B1Service providing method, recording medium, and information processing apparatus
Publication Date: 2019.06.12 FUJITSU LTD
  • EP2634721B1 patent drawingFigure 1
  • EP2634721B1 patent drawingFigure 2
  • EP2634721B1 patent drawingFigure 3

AI summary

A service providing method executed by an information processing apparatus that provides a first service, the method includes receiving role information from a terminal apparatus in use by a user, the role information indicating that a second service provided by another information processing apparatus and a role assigned to the user in the second service; and determining a role assigned to the user in the first service according to the role information and relationship information that indicated a relationship between the local apparatus and the another information processing apparatus, in correspondence to the second service.