Remote identity interaction
US-2024380597-A1 · Nov 14, 2024 · US
US9594895B2 · US · B2
| Field | Value |
|---|---|
| Publication number | US-9594895-B2 |
| Application number | US-201514640092-A |
| Country | US |
| Kind code | B2 |
| Filing date | Mar 6, 2015 |
| Priority date | Mar 11, 2014 |
| Publication date | Mar 14, 2017 |
| Grant date | Mar 14, 2017 |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
An information processing system includes an electronic device; a service providing system including information processing devices connected to the image forming device via a network; a single sign on unit configured to send a request from the electronic device to the service providing system, to acquire authentication information of an external service that performs a process in cooperation with an application operating in the image forming device; an access control unit configured to receive the request from the single sign on unit whose validity has been confirmed, based on a result obtained by using identification information of the single sign on unit, in the service providing system; and a data management unit configured to acquire the authentication information of the external service from a storage unit based on the request from the single sign on unit that is valid, and to provide the authentication information of the external service to the single sign on unit via the access control unit.
Opening claim text (preview).
What is claimed is: 1. An information processing system comprising: an image forming device; a service providing system including one or more information processing devices that are connected to the image forming device via a network; a single sign on unit configured to send a request from the image forming device to the service providing system, to acquire authentication information of a plurality of external services provided by a plurality of external service devices that are connected to the image forming device through the network in cooperation with an application operating in the image forming device; an access control unit configured to receive the request from the single sign on unit whose validity has been confirmed, based on a result of confirming the validity of the requesting unit obtained by using identification information of the single sign on unit, in the service providing system; and a data management unit configured to acquire the authentication information of the external service from a storage unit based on the request from the single sign on unit whose validity has been confirmed, said storage unit being configured to have a setting information table including the authentication information of the plurality of external services, and to provide the authentication information of the plurality of external services to the single sign on unit via the access control unit. 2. The information processing system according to claim 1 , wherein the service providing system includes an application programming interface layer configured to receive the request from the image forming device via the network, and a platform layer configured to perform a process based on the request received by the application programming interface layer, wherein the data management unit includes, in the platform layer, a data acquiring unit configured to acquire the authentication information of the external service from the storage unit, based on the request from the single sign on unit whose validity has been confirmed, and the data management unit includes, in the application programming interface layer, a platform application programming interface hiding unit configured to cause the data acquiring unit to process the request from the single sign on unit, by using the platform application programming interface for receiving the request to the data acquiring unit in the platform layer. 3. The information processing system according to claim 2 , wherein the service providing system includes an authentication unit configured to confirm the validity of the single sign on unit by using the identification information of the single sign on unit, based on whether a storage unit in the platform layer includes the identification information of the single sign on unit. 4. The information processing system according to claim 1 , wherein the data management unit registers the authentication information of the external service in the storage unit in association with the identification information of the single sign on unit, based on the request from the single sign on unit whose validity has been confirmed. 5. The information processing system according to claim 4 , wherein the data management unit registers the authentication information of the external service in an authentication table stored in the storage unit, further in association with identification information of a group for grouping a user of the image forming device, based on the request from the single sign on unit whose validity has been confirmed. 6. The information processing system according to claim 5 , wherein the data management unit provides, to the single sign on unit, the authentication information of the external service that is associated with the identification information of the group, when authentication performed by using the identification information of the group is successful. 7. The information processing system according to claim 1 , wherein the storage unit storing the authentication information of the external service is an information storage device that is connected to the service providing system via the network. 8. An authentication information providing method executed by an information processing system including an image forming device and a service providing system including one or more information processing devices that are connected to the image forming device via a network, the authentication information providing method comprising: sending a request from a single sign on unit of the image forming device to the service providing system, to acquire authentication information of a plurality of external services provided by a plurality of external service devices that are connected to the image forming device through the network in cooperation with an application operating in the image forming device; receiving the request from the single sign on unit whose validity has been confirmed, based on a result of confirming the validity of the single sign on unit obtained by using identification information of the single sign on unit, in the service providing system; and acquiring the authentication information of the external service from a storage unit based on the request from the single sign on unit whose validity has been confirmed, said storage unit being configured to have a setting information table including the authentication information of the plurality of external services, and providing the authentication information of the plurality of external services to the single sign on unit. 9. The information processing system according to claim 1 , wherein the setting information table includes the authentication information of the plurality of external services in association with application ID, tenant ID and user ID of the image forming device, and the data management unit is configured to provide the authentication information of the plurality of external services in association with the application ID, the tenant ID and the user ID of the image forming device to the single sign on unit via the access control unit. 10. The information processing system according to claim 1 , wherein the authentication information includes an encoded user ID and an encoded password of the plurality of external services.
for accessing specific resources, e.g. using Kerberos tickets · CPC title
Secure printing · CPC title
where a single sign-on provides access to a plurality of computers · CPC title
Auditing as a secondary aspect · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.