Performing a security action with regard to an access token based on clustering of access requests
US-2024406160-A1 · Dec 5, 2024 · US
US9860231B2 · US · B2
| Field | Value |
|---|---|
| Publication number | US-9860231-B2 |
| Application number | US-201113288766-A |
| Country | US |
| Kind code | B2 |
| Filing date | Nov 3, 2011 |
| Priority date | Nov 4, 2010 |
| Publication date | Jan 2, 2018 |
| Grant date | Jan 2, 2018 |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
A relay apparatus is connected to a communication apparatus, a service providing apparatus and a browser-equipped apparatus. The relay apparatus includes: a registering unit registering provisional registration information, the provisional registration information being used in an authentication procedure performed between the service providing apparatus and the browser-equipped apparatus; an acquiring unit acquiring permission information representing that use of the service is permitted, the permission information being issued by the service providing apparatus in the authentication procedure; a communication unit transmitting the provisional registration information to the browser-equipped apparatus; a receiving unit receiving input information transmitted from the communication apparatus, the input information being generated in response to the provisional registration information; and a communication unit transmitting the permission information to the communication apparatus which has transmitted the input information if the receiving unit receives the input information.
Opening claim text (preview).
What is claimed is: 1. A relay system comprising: a plurality of service providing apparatuses, each of which is configured to provide at least one of an upload service of an electronic file and a download service of an electronic file; a relay apparatus configured to communicate with the plurality of service providing apparatuses through the Internet, the relay apparatus being configured to request the plurality of service providing apparatuses to transmit upload destination information which is used for requesting the plurality of service providing apparatuses to provide at least one of the upload service and the download service; a communication terminal configured to communicate with the relay apparatus through the Internet, the communication terminal being configured to request the plurality of service providing apparatus to provide at least one of the upload service and the download service using the upload destination information; and a browser-equipped apparatus which is provided with a browser and is configured to transmit a first request to the relay apparatus in response to receiving a first user input, wherein the relay apparatus includes: a first communication unit; a first storage; and a first controller, wherein the communication terminal includes: a second communication unit; a display unit; an input receipt unit; a second storage; and a second controller, wherein the first controller of the relay apparatus controls the first communication unit to transmit first screen data to the browser-equipped apparatus in response to receiving from the browser-equipped apparatus via the first communication unit the first request, wherein the first screen data causes the browser-equipped apparatus to display a first screen which allows a user to select one of the plurality of service providing apparatuses; wherein the browser-equipped apparatus displays the first screen in response to receiving the first screen data, and transmits a second request to the first communication unit in response to the user selecting one of the plurality of service providing apparatuses through the first displayed screen, the second request including information indicative of the service providing apparatus selected by the user; wherein the first controller of the relay apparatus controls the first communication unit to transmit, to the browser-equipped apparatus, in response to receiving the second request transmitted from the browser-equipped apparatus after the first communication unit transmits the first screen data: a first command which commands the browser-equipped apparatus to access a login page of the selected service providing apparatus; and a URL indicative of the relay apparatus; wherein the browser-equipped apparatus accesses the login page of the selected service providing apparatus according to the first command and transmits, to the selected service providing apparatus, the URL and a first account and a first password which are input by the user; wherein in response to receiving the first account and the first password, the selected service providing apparatus determines whether the first account and the first password correspond to a second account, indicative of a user registered in the selected service providing apparatus, and a second password of the second account; wherein if the first account and the first password correspond to the second account and the second password, the selected service providing apparatus issues first authentication information, and transmits, to the browser-equipped apparatus, a second command which is a command for redirecting to the relay apparatus and includes the URL received from the browser-equipped apparatus; wherein the browser-equipped apparatus accesses the relay apparatus according to the URL included in the second command and transmits to the relay apparatus a third request which includes the first authentication information included in the second command; wherein in response to receiving the third request, the first controller of the relay apparatus issues first provisional registration information, and stores, in the first storage, the issued first provisional registration information, the first authentication information included in the third request and second identification information for identifying the selected service providing apparatus in such a manner that the first provisional registration information, the first authentication information and the second identification information are associated with each other; wherein the first controller of the relay apparatus controls the first communication unit to transmit the first provisional registration information to the browser-equipped apparatus; wherein in response to receiving the first provisional registration information transmitted from the relay apparatus, the browser-equipped apparatus displays the received first provisional registration information; wherein in response to receiving a second user input by the input receipt unit, the second controller of the communication terminal controls the second communication unit to transmit a fourth request to the first communication unit of the relay apparatus; wherein in response to receiving the fourth request, the first controller of the relay apparatus controls the first communication unit to transmit, to the communication terminal, second screen data which causes the communication terminal to display a second screen which allows the user to input second provisional registration information; wherein in response to receiving, by the second communication unit, the second screen data transmitted from the relay apparatus, the second controller of the communication terminal controls the display unit to display the second screen; wherein after the display unit displays the second screen, the second controller of the communication terminal controls the second communication unit to transmit to the relay apparatus the second provisional registration information received by the input receipt unit; wherein the first controller of the relay apparatus determines whether the second provisional registration information received by the first communication unit corresponds to the first provisional registration information stored in the first storage; wherein if the first controller determines that the second provisional registration information corresponds to the first provisional registration information stored in the first storage, the first controller controls the first communication unit to transmit a fifth request which includes the first authentication information associated with the first provisional registration information and stored in the first storage, to the service providing apparatus which is identified by the second identification information which corresponds to the first provisional registration information and is stored in the first storage; wherein the service providing apparatus identified by the second identification information determines whether the first authentication information included in the received fifth request is stored in the service providing apparatus identified by the second identification information; wherein if the service providing apparatus identified by the second identification information determines that the first authentication information stored in the received fifth request is stored in the service providing apparatus identified by the second identification information, the service providing apparatus identified by the second identification information issues an access token and transmits the issued access token to the relay apparatus which transmitted the fifth request; wherein in response to receiving, by the first communication unit, the access token, the first controller of the relay apparatus controls the first communication unit to transmit the received access token to the communicat
applying security measure for e-commerce · CPC title
Entity profiles · CPC title
using tickets, e.g. Kerberos (cryptographic mechanisms or cryptographic arrangements for entity authentication using tickets or tokens H04L9/3213) · CPC title
for authentication of entities (cryptographic mechanisms or cryptographic arrangements for entity authentication H04L9/32) · CPC title
Access control lists [ACL] · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.