IP Library › Granted Patent US 12,177,228
Granted Patent B2
US 12,177,228 · App. 17/744,516 · Granted Dec 24, 2024

Authorization server, system, and method for system

Inventor: Kazunari Yamanakajima (Kanagawa, JP)
Assignee: Canon Kabushiki Kaisha
H04L63/108H04L63/0807H04L63/102
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,177,228
App. No.
17/744,516
Granted
Dec 24, 2024
Kind
B2
Abstract

After receiving an authorization result from a user, an authorization server sets a deadline for re-authorization, performs wait processing until the deadline, and thereafter issues an access token.

Claims (34)

1. An authorization server in a system including a resource server configured to provide a resource of a user, a client configured to access the resource, the authorization server configured to issue an access token indicating approval by the user for access of the client to the resource, and a user terminal, the authorization server comprising:

at least one first processer and at least one first memory coupled to the first processor and having stored thereon instructions,

when executed by the first processor, and cooperating to act as:

a reception unit configured to receive an authorization start request from the client;

an identification unit configured to identify, in a case where the authorization start request is received by the reception unit, the user terminal that is a transmission destination of an authorization check request;

an authorization unit configured to transmit the authorization check request to the identified user terminal, receive an authorization check result as a response, and temporarily store the authorization check result for a time period during which re-authorization is allowed; and

an issuance unit configured to control, in response to expiration of the time period during which re-authorization is allowed, issuance of the access token based on the authorization check result stored temporarily, and transmit, in a case where the issuance unit issues the access token, the access token to the client from which the authorization start request has been transmitted,

wherein, in a case where the authorization start request received by the reception unit is a request specifying that re-authorization is not allowed, the issuance unit controls issuance of the access token based on the authorization check result without waiting for expiration of the time period during which re-authorization is allowed.

2. The authorization server according to claim 1 , wherein, in response to expiration of the time period during which re-authorization is allowed, the issuance unit checks the authorization check result stored temporarily, and in a case where the access token is not to be issued, the issuance unit transmits information indicating disapproval to the client after expiration of the time period during which re-authorization is allowed.

3. The authorization server according to claim 1 , wherein, in a case where the authorization unit receives a re-authorization instruction from the client, the authorization unit updates the authorization check result stored temporarily, based on the re-authorization instruction.

4. The authorization server according to claim 1 , wherein the time period is set based on a value calculated from a time and date of receipt of the authorization check result and a preset value or based on a value designated by the authorization start request transmitted from the client.

5. The authorization server according to claim 1 , wherein, in a case where the authorization start request received by the reception unit is a request specifying that re-authorization is not allowed, the authorization unit does not temporarily store the received authorization check result.

6. The authorization server according to claim 1 , wherein, in a case where the authorization start request received by the reception unit is a request specifying that re-authorization is allowed, information indicating receipt of an authorization result and an authorization deadline are transmitted to the user terminal.

7. A system including a resource server configured to provide a resource of a user, a client configured to access the resource, the authorization server configured to issue an access token indicating approval by the user for access of the client to the resource, and a user terminal, the system comprising:

at least one first processer and at least one first memory coupled to the first processor and having stored thereon instructions,

when executed by the first processor, and cooperating to act as:

a reception unit configured to receive an authorization start request from the client;

an identification unit configured to identify, in a case where the authorization start request is received by the reception unit, the user terminal that is a transmission destination of an authorization check request;

a transmission unit configured to transmit the authorization check request to the identified user terminal;

a first reception unit configured to display an authorization check item of the authorization check request and receive an approval instruction or a disapproval instruction to the authorization check request;

an authorization unit configured to receive an authorization check result as a response to the authorization check request and temporarily store the authorization check result for a time period during which re-authorization is allowed;

a second reception unit configured to receive a re-authorization instruction after receipt of the approval instruction or the disapproval instruction to the authorization check request; and

an issuance unit configured to control, in response to expiration of the time period during which re-authorization is allowed, issuance of the access token based on the authorization check result stored temporarily, and transmit, in a case where the issuance unit issues the access token, the access token to the client from which the authorization start request has been transmitted,

wherein, in a case where the authorization start request received by the reception unit is a request specifying that re-authorization is not allowed, the issuance unit controls issuance of the access token based on the authorization check result without waiting for expiration of the time period during which re-authorization is allowed.

8. The system according to claim 7 , wherein the second reception unit is configured not to receive a re-authorization instruction to the authorization check request after expiration of the time period during which re-authorization is allowed.

9. A method that is performed by a system including a resource server configured to provide a resource of a user, a client configured to access the resource, the authorization server configured to issue an access token indicating approval by the user for access of the client to the resource, and a user terminal, the method comprising:

receiving an authorization start request from the client;

identifying, in a case where the authorization check request is received, the user terminal that is a transmission destination of an authorization check request;

transmitting the authorization check request to the identified user terminal;

displaying an authorization check item of the authorization check request and receiving an approval instruction or a disapproval instruction to the authorization check request;

receiving, as first receiving, an authorization check result as a response to the authorization check request and temporarily storing the authorization check result for a time period during which re-authorization is allowed;

receiving, as second receiving, a re-authorization instruction after receipt of the approval instruction or the disapproval instruction to the authorization check request; and

controlling, in response to expiration of the time period during which re-authorization is allowed, issuance of the access token based on the authorization check result stored temporarily, and transmitting, in a case where the access token is issued, the access token to the client from which the authorization start request has been transmitted,

wherein, in a case where the authorization start request is a request specifying that re-authorization is not allowed, the controlling controls issuance of the access token based on the authorization check result without waiting for expiration of the time period during which re-authorization is allowed.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 9, 2022
From: YAMANAKAJIMA, KAZUNARI
To: CANON KABUSHIKI KAISHA
Reel/Frame 060329/0477 →
Priority Claims (1)
JP 2019-208994 · Nov 19, 2019 · national
Continuity (2)
Continuation PCTJP2020041802 · Nov 10, 2020
Related Publication 20220272104A1 · Aug 25, 2022