Authority transfer system, method that is executed by authority transfer system, and storage medium

US2016119351A1 · US · A1

Patent metadata
FieldValue
Publication numberUS-2016119351-A1
Application numberUS-201514921932-A
CountryUS
Kind codeA1
Filing dateOct 23, 2015
Priority dateOct 27, 2014
Publication dateApr 28, 2016
Grant date

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

An authority transfer system enables omitting authorization of a user belonging to a tenant based on an authorization operation being performed at least once on a terminal associated with the tenant.

First claim

Opening claim text (preview).

What is claimed is: 1 . An authority transfer system, which includes a terminal, a server that provides a service via a network, and a client that uses the service, the authority transfer system comprising: an authentication unit configured to determine, based on authentication information input by a user via an authentication screen displayed on the terminal, whether the user is an authorized user; an issuance unit configured to, in a case where the user determined by the authentication unit to be an authorized user has performed, via an authorization screen displayed on the terminal, an authorization operation to permit an authority of the user in the service to be transferred to the client provided in the terminal, issue authorization information indicating that the authority of the user has been transferred to the client; an authorization unit configured to authorize the client to use the service by the authority of the user based on the authorization information, which the terminal transmits to the client when the client makes a request to use the service; and a checking unit configured to check with the user whether to perform, on a tenant to which the user who has been determined by the authentication unit to be an authorized user belongs, a setting such that, when an additional user belonging to the tenant uses the service via the client provided in the terminal, the authorization information corresponding to the client is issued without the additional user performing the authorization operation, wherein, in response to the user performing the setting such that, when an additional user belonging to the tenant uses the service via the client provided in the terminal, the authorization information is issued without the additional user performing the authorization operation, the authorization unit authorizes the additional user to use the service without performing the authorization operation when the additional user uses the service via the client provided in the terminal. 2 . The authority transfer system according to claim 1 , wherein, in response to the user performing the setting such that when an additional user belonging to the tenant uses the service via the client provided in the terminal, the authorization information is issued without the additional user performing the authorization operation, and to, when the additional user uses the service via a client provided in an additional terminal, authorization information corresponding to the client provided in the additional terminal having already been issued by the issuance unit according to the authorization operation performed by the additional user, the authorization unit authorizes the additional user to use the service without performing the authorization operation when the additional user uses the service via the terminal. 3 . The authority transfer system according to claim 1 , further comprising a determination unit configured to determine whether a type of the terminal that the user uses is a common setting terminal in which common setting is set, wherein, in a case where the determination unit determines that the type of the terminal is the common setting terminal, the checking unit checks with the user whether to perform, on a tenant to which the user who has been determined by the authentication unit to be an authorized user belongs, a setting such that, when an additional user belonging to the tenant uses the service via the client provided in the terminal, the authorization information corresponding to the client is issued without the additional user performing the authorization operation. 4 . The authority transfer system according to claim 3 , wherein, in a case where the determination unit determines that the type of the terminal is not the common setting terminal, the checking unit checks with the user whether to perform, on the user who has been determined by the authentication unit to be an authorized user, a setting such that, when the user uses the service via a client provided in an additional terminal, the authorization information corresponding to the client provided in the additional terminal is issued without the user performing the authorization operation. 5 . The authority transfer system according to claim 1 , further comprising a management unit configured to, in response to the checking unit checking that a setting has been performed on the tenant such that the authorization information is issued without an additional user belonging to the tenant performing the authorization operation, manage a client identifier for identifying the client provided in the terminal and an identifier of the tenant specified based on an identifier of the user who has been determined by the authentication unit to be an authorized user while associating the client identifier and the identifier of the tenant with each other, wherein the authorization unit specifies an identifier of the additional user based on authentication information input by the additional user, and, in response to an identifier of the terminal that the additional user uses being associated with the identifier of the tenant associated with the specified identifier of the additional user, authorizes the additional user to use the service without performing the authorization operation when the additional user uses the service via the terminal. 6 . A method executed by an authority transfer system, which includes a terminal, a server that provides a service via a network, and a client that uses the service, the method comprising: determining, based on authentication information input by a user via an authentication screen displayed on the terminal, whether the user is an authorized user; issuing, in a case where the user determined to be an authorized user has performed, via an authorization screen displayed on the terminal, an authorization operation to permit an authority of the user in the service to be transferred to the client provided in the terminal, authorization information indicating that the authority of the user has been transferred to the client; authorizing the client to use the service by the authority of the user based on the authorization information, which the terminal transmits to the client when the client makes a request to use the service; checking with the user whether to perform, on a tenant to which the user who has been determined to be an authorized user belongs, a setting such that, when an additional user belonging to the tenant uses the service via the client provided in the terminal, the authorization information corresponding to the client is issued without the additional user performing the authorization operation; and authorizing, in response to the user performing the setting such that, when an additional user belonging to the tenant uses the service via the client provided in the terminal, the authorization information is issued without the additional user performing the authorization operation, the additional user to use the service without performing the authorization operation when the additional user uses the service via the client provided in the terminal. 7 . The method according to claim 6 , further comprising authorizing, in response to the user performing the setting such that when an additional user belonging to the tenant uses the service via the client provided in the terminal, the authorization information is issued without the additional user performing the authorization operation, and to, when the additional user uses the service via a client provided in an additional terminal, authorization information corresponding to the client provided in the additional terminal having already been issued according to the authorization operation performed by the additional user, the additional u

Assignees

Inventors

Classifications

  • H04L63/10Primary

    for controlling access to devices or network resources · CPC title

  • for authentication of entities (cryptographic mechanisms or cryptographic arrangements for entity authentication H04L9/32) · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US2016119351A1 cover?
An authority transfer system enables omitting authorization of a user belonging to a tenant based on an authorization operation being performed at least once on a terminal associated with the tenant.
Who is the assignee on this patent?
Canon Kk
What technology area does this patent fall under?
Primary CPC classification H04L63/10. Mapped technology areas include Electricity.
When was this patent published?
Publication date Thu Apr 28 2016 00:00:00 GMT+0000 (Coordinated Universal Time) (A1). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 12 related publications on this page (citations in our corpus or others sharing the same primary CPC).