Image Forming Apparatus Single Sign-On Token Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing systems for image forming apparatuses that cooperate with cloud services using OAuth face challenges in convenient user authentication, as users often need to log in multiple times, and there is a risk of unauthorized access when sharing authorization tokens among multiple applications.
Innovation Solution
The image forming apparatus is equipped with a processor that manages local login information and determines whether to use an internal communication address for authorization requests, allowing it to associate authorization tokens with local login information, thereby enabling single sign-on and reducing the need for multiple logins while preventing unauthorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If an image forming apparatus shares authorization tokens with multiple users for cloud service access, then service cooperation is enabled, but unauthorized access risk increases
Solution Approach 1:
The patent segments the authorization token management by creating separate token storage areas for different users and applications. The authorization token is divided into user-specific portions, ensuring that each user can only access their own cloud service resources. This segmentation prevents unauthorized access while maintaining service cooperation capabilities.
Solution Approach 2:
The image forming apparatus acts as an intermediary between users and cloud services, managing authorization tokens centrally. It verifies user identities and controls token distribution, preventing direct unauthorized access between users and cloud services while enabling legitimate service cooperation.
2Reliability
If users log in multiple times to different applications, then each application can be authenticated, but user convenience decreases
Solution Approach 1:
The system performs preliminary authentication by storing authorization tokens after the first successful login. Subsequent applications can utilize these pre-stored tokens without requiring users to log in again, maintaining security while improving convenience for repeated access scenarios.
Solution Approach 2:
The image forming apparatus automatically manages authorization tokens and handles authentication processes without requiring user intervention for each application. The system self-service aspect includes automatic token retrieval, validation, and distribution to authorized applications.
3Reliability
If authorization tokens are stored in the image forming apparatus, then access control is improved, but device complexity increases
Solution Approach 1:
The image forming apparatus utilizes its existing authentication infrastructure and storage capabilities to manage authorization tokens, rather than introducing completely new components. This multi-functional approach leverages existing device resources, reducing the increase in complexity while improving access control.
Data Source
AI summary
An image forming apparatus that communicates with an external apparatus includes receiving local login information regarding a local login to the image forming apparatus, determining, if a request for a URL for authorization without web access authentication is received, whether an internal communication address is used, requesting, if it is determined that the internal communication address is used, authorization request for the external apparatus, and managing an authorization token acquired by requesting the authorization request and the local login information by associating the authorization token with the local login information.


