SSO User ID Linking Verification via Unique Management IDs

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In single sign-on (SSO) systems, malicious administrators can incorrectly link user IDs by registering unrelated IDs, leading to potential ID theft and management issues, even with good intentions, due to reliance on email address verification which may result in mistaken consent.

Innovation Solution

A management device that requires unique internal management IDs for verification, prompting users to input these IDs during the linking process, ensuring only genuine users can link their accounts, thereby preventing unauthorized ID linking.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If email address verification is used for user ID linking in SSO, then the linking process is simple and fast, but malicious administrators can incorrectly link unrelated user IDs leading to ID theft

Engineering Contradiction:
Improvelinking process efficiencyVSAvoiduser ID linking accuracy
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent introduces an intermediary verification step using a notification email sent to the user's registered email address. This intermediary mechanism mediates between the administrator's linking request and the actual ID association, ensuring that only authorized users can confirm the linking operation, thereby preventing malicious or erroneous ID linking while maintaining operational efficiency.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If administrators have direct authority to link user IDs, then the operation is convenient and quick, but mistakes or malicious actions can occur without verification

Engineering Contradiction:
Improveadministrator operation convenienceVSAvoidID theft risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary anti-action by sending a verification email to the user before the ID linking is finalized. This preliminary countermeasure prevents harmful actions (malicious or erroneous linking) by requiring user confirmation in advance, thus neutralizing potential threats before they can cause damage while still allowing legitimate operations to proceed smoothly.

Inventive Principle:
Principle #9Preliminary anti-action

3Device complexity

If no verification mechanism is implemented, then the system is simple and operations are fast, but security vulnerabilities arise allowing unauthorized ID linking

Engineering Contradiction:
Improvesystem structure simplicityVSAvoidsecurity reliability
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent implements self-service by enabling users to verify and confirm their own ID linking through email notification. Instead of relying on complex administrative verification systems, the user themselves performs the verification by clicking a confirmation link in the email, thus enhancing security through user autonomy while keeping the system structure relatively simple.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11784994B2Management device, management system, and non-transitory computer readable medium
Publication Date: 2023.10.10 FUJIFILM BUSINESS INNOVATION CORP
  • US11784994B2 patent drawing
  • US11784994B2 patent drawing
  • US11784994B2 patent drawing

AI summary

A management device includes a receiving unit that receives a link request to link a user ID of a user from a link origin, and a control unit that, in response the link request, requests the user to input unique information of the link origin, and does not execute a linking of the user ID in a case in which the unique information input from the user is incorrect.