Unified Authority Information Provisioning for Multi-Service Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In cloud computing and mashup service environments, users face the inconvenience of multiple permission procedures when accessing and utilizing services from different service providers, leading to increased complexity and management costs due to the need for individual authentication and permission handling by each service application.

Innovation Solution

A system with a first service providing system and a second service providing system, featuring a connection destination changing unit, an authority information acquiring unit, and an authority information providing unit, which simplifies the permission process by allowing a single user to request and manage permission for multiple services through a unified authentication infrastructure, reducing the number of permission procedures required.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If individual authentication and permission handling is performed by each service application, then service security is maintained, but the number of permission procedures increases and management complexity increases

Engineering Contradiction:
Improveservice securityVSAvoidmanagement complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges multiple authentication and permission handling operations into a single unified permission procedure. The authority information providing apparatus consolidates the OAuth client functions of multiple service applications, allowing a user to grant permission for multiple services simultaneously through one authorization flow, rather than performing separate authentication for each service application

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The authority information providing apparatus serves multiple service applications universally by centralizing the permission management function. A single permission grant issued by the user can be utilized across multiple service applications that share the same authority information, making the authentication infrastructure multi-functional and applicable to various services without requiring separate permission procedures for each

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If individual permission procedures are required for each service, then service-specific authentication control is maintained, but user burden increases and usability decreases

Engineering Contradiction:
Improveauthentication controlVSAvoiduser burden
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

Multiple service-specific authentication controls are merged into a single unified permission procedure. The system combines the authorization flows of multiple service applications so that the user performs one permission grant operation that covers all services, significantly reducing the repetitive authentication actions the user must perform

Inventive Principle:
Principle #5Merging (Combining)

3Adaptability or versatility

If separate OAuth client functions are implemented in each service application, then service independence is maintained, but development and management costs increase

Engineering Contradiction:
Improveservice independenceVSAvoiddevelopment cost
Core Design Contradiction:
Adaptability or versatilityVSEase of manufacture

Solution Approach 1:

The patent extracts the OAuth client functions from individual service applications and consolidates them into a separate authority information providing apparatus. This extraction allows service applications to maintain their independence and business logic while sharing the common authentication infrastructure, reducing redundant development and management costs across multiple services

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS9288213B2System and service providing apparatus
Publication Date: 2016.03.15 RICOH CO LTD
  • US9288213B2 patent drawing
  • US9288213B2 patent drawing
  • US9288213B2 patent drawing

AI summary

A disclosed system having a first service providing system providing a service to an apparatus and a second service providing system having an authentication infrastructure different from that of the first service providing system includes a connection destination changing unit receiving a permission request, from an apparatus operated by a first user, of requesting that a second user uses the second service providing system, changes a connection destination of the apparatus to the second service providing system, and causes the second service providing system to perform a permission process; an authority information acquiring unit receiving permission information indicating that the permission request is admitted from the apparatus and acquires post-permission authority information by using the permission information; and an authority information providing unit providing the post-permission authority information associated with the second user based on a request for a process received from another apparatus operated by the second user.