Unified Authority Information Provisioning for Multi-Service Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In cloud computing and mashup service environments, users face the inconvenience of multiple permission procedures when accessing and utilizing services from different service providers, leading to increased complexity and management costs due to the need for individual authentication and permission handling by each service application.
Innovation Solution
A system with a first service providing system and a second service providing system, featuring a connection destination changing unit, an authority information acquiring unit, and an authority information providing unit, which simplifies the permission process by allowing a single user to request and manage permission for multiple services through a unified authentication infrastructure, reducing the number of permission procedures required.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If individual authentication and permission handling is performed by each service application, then service security is maintained, but the number of permission procedures increases and management complexity increases
Solution Approach 1:
The patent merges multiple authentication and permission handling operations into a single unified permission procedure. The authority information providing apparatus consolidates the OAuth client functions of multiple service applications, allowing a user to grant permission for multiple services simultaneously through one authorization flow, rather than performing separate authentication for each service application
Solution Approach 2:
The authority information providing apparatus serves multiple service applications universally by centralizing the permission management function. A single permission grant issued by the user can be utilized across multiple service applications that share the same authority information, making the authentication infrastructure multi-functional and applicable to various services without requiring separate permission procedures for each
2Reliability
If individual permission procedures are required for each service, then service-specific authentication control is maintained, but user burden increases and usability decreases
Solution Approach 1:
Multiple service-specific authentication controls are merged into a single unified permission procedure. The system combines the authorization flows of multiple service applications so that the user performs one permission grant operation that covers all services, significantly reducing the repetitive authentication actions the user must perform
3Adaptability or versatility
If separate OAuth client functions are implemented in each service application, then service independence is maintained, but development and management costs increase
Solution Approach 1:
The patent extracts the OAuth client functions from individual service applications and consolidates them into a separate authority information providing apparatus. This extraction allows service applications to maintain their independence and business logic while sharing the common authentication infrastructure, reducing redundant development and management costs across multiple services
Data Source
AI summary
A disclosed system having a first service providing system providing a service to an apparatus and a second service providing system having an authentication infrastructure different from that of the first service providing system includes a connection destination changing unit receiving a permission request, from an apparatus operated by a first user, of requesting that a second user uses the second service providing system, changes a connection destination of the apparatus to the second service providing system, and causes the second service providing system to perform a permission process; an authority information acquiring unit receiving permission information indicating that the permission request is admitted from the apparatus and acquires post-permission authority information by using the permission information; and an authority information providing unit providing the post-permission authority information associated with the second user based on a request for a process received from another apparatus operated by the second user.


