Information Processing System Token Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In data communications, devices without Web browser support for authorization servers face challenges in obtaining access tokens, and the exchange of credential information between devices can lead to unauthorized acquisition of token information through spoofing.

Innovation Solution

An information processing system that includes processors to receive user login, extract identification information from issued tokens, and compare it with login information to verify access, preventing unauthorized access by ensuring matching user IDs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If credential information is exchanged between devices to enable authorization, then devices without Web browser support can obtain access tokens, but the risk of unauthorized acquisition of token information through spoofing increases

Engineering Contradiction:
Improvedevice compatibilityVSAvoidspoofing risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a credential information management unit that acts as an intermediary between the authorization server and external apparatus. This intermediary securely manages credential information, extracts necessary components, and transmits them through controlled channels, thereby enabling device compatibility while mitigating spoofing risks through centralized security control

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary actions by pre-establishing secure credential information in the credential information management unit before authorization requests are made. The credential information is extracted and prepared in advance with proper security measures, so that when authorization is needed, the pre-prepared secure credentials can be used without exposing the system to spoofing during the authorization process

Inventive Principle:
Principle #10Preliminary action

2Ease of operation

If screen display method is used to exchange information between devices, then information can be transmitted visually, but the information may be stolen at a glance or illegally captured

Engineering Contradiction:
Improveinformation exchangeVSAvoidinformation theft
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent extracts only the necessary credential information components from the complete credential set and transmits only these extracted portions through the authorization process. By taking out and transmitting only the minimal required information through controlled channels rather than displaying complete credential information on screens, the system enables information exchange while reducing the risk of information theft

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The credential information management unit serves as an intermediary that handles the extraction and transmission of credential information without requiring visual display on screens. This intermediary manages the information exchange process securely, transmitting data through programmed communication channels that prevent casual observation or illegal capture

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20240411848A1Information processing system and non-transitory computer readable medium
Publication Date: 2024.12.12 FUJIFILM BUSINESS INNOVATION CORP
  • US20240411848A1 patent drawing
  • US20240411848A1 patent drawing
  • US20240411848A1 patent drawing

AI summary

An information processing system includes one or more processors configured to: receive a login from a user; extract identification information on the user from an identification (ID) token if an access token and the ID token that an authorization server has issued in response to a request from an external apparatus are acquired; and compare, with the identification information on the user extracted from the ID token, identification information on the user acquired when the login is received and permit access based on the access token if the identification information on the user acquired during the login matches the identification information on the user extracted from the ID token.