Single Sign-On ID Mapping Verification System

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing single sign-on (SSO) systems face challenges in establishing accurate mapping between identity provider (IdP) and service provider (SP) IDs, leading to inefficiencies in user authentication and service access, particularly in scenarios where administrator authority is required for collective SSO settings across different services.

Innovation Solution

A system that includes an acquisition unit for gathering authentication information, an acceptance unit for verifying correspondence between IdP and SP IDs, and a setting unit that configures SSO mapping only when both conditions are met, ensuring secure and accurate ID mapping without requiring users to share passwords.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If SSO mapping is set without verification, then setup speed is improved, but mapping accuracy deteriorates

Engineering Contradiction:
ImproveSSO mapping setup speedVSAvoidID mapping accuracy
Core Design Contradiction:
ProductivityVSMeasurement precision

Solution Approach 1:

The system performs preliminary verification by acquiring authentication information from both the first information processing system and the second information processing system before setting the SSO mapping. This preliminary action ensures that the correspondence between IDs is verified in advance, preventing incorrect mappings while maintaining efficient setup processes.

Inventive Principle:
Principle #10Preliminary action

2Measurement precision

If authentication information is verified from both systems, then mapping accuracy is improved, but system complexity increases

Engineering Contradiction:
ImproveID mapping accuracyVSAvoidauthentication verification complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The second information processing system acts as an intermediary that receives correspondence information indicating the relationship between first authentication information and second authentication information. The system uses this intermediary mechanism to verify mappings without requiring direct complex interactions between multiple authentication systems, thereby reducing overall system complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If SSO mapping is set without conditions, then ease of operation is improved, but security deteriorates

Engineering Contradiction:
ImproveSSO configuration simplicityVSAvoidauthentication security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system implements a feedback mechanism where the setting unit receives confirmation results from the verification process. Based on this feedback, the setting unit determines whether to set the correspondence information as single sign-on setting information. This feedback loop ensures that only verified, accurate mappings are established, maintaining security while preserving ease of operation through automated decision-making.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS9077708B2Information processing system, control method for controlling the information processing system, and storage medium
Publication Date: 2015.07.07 CANON KK
  • US9077708B2 patent drawing
  • US9077708B2 patent drawing
  • US9077708B2 patent drawing

AI summary

A second information processing system to communicate with a first information processing system includes an acquisition unit, an acceptance unit, a confirmation unit, and a setting unit. The acquisition unit acquires authentication information from the first information processing system and from a memory of the second information processing system. The acceptance unit accepts correspondence information indicating correspondence between first authentication information and second authentication information. The confirmation unit confirms, as a condition, whether the acquired authentication information in the first information processing system is identical to the accepted first authentication information and confirms, as a condition, whether the acquired authentication information in the second information processing system is identical to the accepted second authentication information. The setting unit does not set the correspondence information as single sign-on setting information if a condition is not satisfied and sets the correspondence information as single sign-on setting information if both conditions are satisfied.