Federated Authentication System with Organization-Specific Trust Circles

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional Identity Providers (IdP) in cloud computing lack the flexibility to accommodate variations in service providers (SP) across different organizations, making it difficult to establish a trust relationship for authentication.

Innovation Solution

An information processing system that receives user and organization identification information, performs authentication using storage units to associate user information with organization information, and sends federated authentication responses when the organization is linked to external services with established trust relationships.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a conventional IdP is used for authentication, then authentication can be performed for services, but flexibility to accommodate variations in service providers across different organizations is lacking

Engineering Contradiction:
Improveflexibility in establishing trust relationshipVSAvoidcomplexity of trust relationship establishment
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the trust relationship establishment by introducing organization-specific trust circles. Each organization can define its own trust circle containing organization-specific service providers, separating the global IdP functionality from local SP variations. This allows flexible accommodation of different organizations' service providers without affecting other organizations.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements dynamic trust circle configuration where organizations can add, remove, and modify service providers within their trust circles as needed. The system dynamically determines which trust circle applies based on the organization identifier, enabling flexible adaptation to changing service provider requirements across different organizations.

Inventive Principle:
Principle #15Dynamics

2Adaptability or versatility

If organization-specific trust circles are implemented, then flexibility for multiple organizations is improved, but system complexity increases

Engineering Contradiction:
Improveaccommodation of service provider variationsVSAvoidtrust circle management structure
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary layer (the organization identifier and trust circle mapping mechanism) between the global IdP and various service providers. This intermediary automatically routes authentication requests to the appropriate organization-specific trust circle, managing the complexity of multiple trust circles without burdening the user or service providers.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates a universal trust circle structure that can accommodate any organization's service providers. The same basic trust circle framework serves multiple organizations simultaneously, each with their own customized service provider lists, reducing overall system complexity through standardized multi-functional design.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9210159B2Information processing system, information processing device, and authentication method
Publication Date: 2015.12.08 RICOH CO LTD
  • US9210159B2 patent drawing
  • US9210159B2 patent drawing
  • US9210159B2 patent drawing

AI summary

An information processing system includes a receiving unit that receives user identification information and organization identification information from an external device, and an authentication unit that performs authentication of the user identification information and the organization identification information received by the receiving unit using a first storage unit storing one or more sets of user identification information in association with organization identification information. When the authentication unit receives a federated authentication request to access an external service from the external device that is authenticated, the authentication unit sends a federated authentication response to the external device if the organization identification information received from the external device and the external service designated in the federated authentication request are associated with each other in a second storage unit storing the organization identification information in association with information on one or more external services that have established a trust relationship for authentication.