IP Library Granted Patent US 10,412,075
Granted Patent B2
US 10,412,075 · App. 15/802,555 · Granted Sep 10, 2019

Authorization server, non-transitory computer-readable medium, and authority delegating system

Inventor: Hayato Matsugashita (Kawasaki, JP)
Assignee: Canon Kabushiki Kaisha
H04L63/0807G06F21/335G06F21/6263H04L9/0833H04L9/3213H04L63/10H04L67/02
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,412,075
App. No.
15/802,555
Granted
Sep 10, 2019
Kind
B2
Abstract

An authorization server, comprises: receiving from a client an authorization request in which a scope group, with which one or a plurality of scopes that define an extent for using a Web service are associated, is designated; presenting to a user, in a case where one or more scopes among the one or a plurality of scopes associated with the scope group are included in an extent of an authority that the user has, a screen for accepting an authorization operation corresponding to the authorization request; issuing to the client, in accordance with accepting the authorization operation of the user corresponding to the authorization request via the screen, authorization information relating to the scope group; and issuing, in accordance with accepting an authorization token request based on the issued authorization information, an authorization token corresponding to the scope group.

Claims (45)

1. An authorization server, comprising:

a memory storing instructions, and

at least one processor executing the instructions to cause the authentication server to:

receive from a client an authorization request in which a scope group, with which one or a plurality of scopes that define an extent for using a Web service are associated, is designated;

present to a user, in a case where one or more scopes among the one or a plurality of scopes associated with the scope group are included in an extent of an authority that the user has, a screen for accepting an authorization operation corresponding to the authorization request;

issue to the client, in accordance with accepting the authorization operation of the user corresponding to the authorization request via the screen, authorization information relating to the scope group; and

issue, in accordance with accepting an authorization token request based on the issued authorization information, an authorization token corresponding to the scope group,

wherein upon issuing an authorization token corresponding to the scope group, an authorization token that is signed with reciting only scopes in the extent of the authority that the user currently has is issued,

upon issuing an authorization token corresponding to the scope group, a refresh token for reissuing the authorization token is issued additionally,

in a case where a request to reissue the authorization token using the refresh token is accepted, the authorization token is reissued based on the one or a plurality of scopes associated with the scope group when the request to reissue was accepted, and

verification of the authorization token is performed by a resource server for providing a Web service.

2. The authorization server according to claim 1 , wherein upon accepting an authorization operation of a user, the user is presented that the client will become capable of using the Web service in the extent of the one or a plurality of scopes associated with the scope group.

3. The authorization server according to claim 1 , wherein upon accepting the authorization token request, the authorization token is issued in a case where the one or more scopes among the one or a plurality of scopes associated with the authorization information are included in an extent of authority that the user has.

4. The authorization server according to claim 1 , wherein upon reissuing the authorization token, a new refresh token is additionally issued.

5. The authorization server according to claim 1 , wherein upon issuing the authorization token, signature information is added.

6. The authorization server according to claim 5 , wherein for the authorization token, a JSON Web Token is used, and

for the signature information, a JSON Web Signature is used.

7. An authority delegating system including a resource server for providing a Web service, and an authorization server, wherein

the authorization server comprises:

a memory storing instructions, and

at least one processor executing the instructions to cause the authentication server to:

receive from a client an authorization request in which a scope group, with which one or a plurality of scopes that define an extent for using a Web service are associated, is designated;

present to a user, in a case where one or more scopes among the one or a plurality of scopes associated with the scope group are included in an extent of an authority that the user has, a screen for accepting an authorization operation corresponding to the authorization request;

issue to the client, in accordance with accepting the authorization operation of the user corresponding to the authorization request via the screen, authorization information relating to the scope group; and

issue, in accordance with accepting an authorization token request based on the authorization information issued by the authorization server, an authorization token corresponding to the scope group, and

the resource server comprises:

a memory storing instructions, and

at least one processor executing the instructions to cause the resource server to:

accept a Web service usage request made using the authorization token;

perform verification of the authorization token; and

provide the Web service based on a result of the verification,

wherein upon issuing an authorization token corresponding to the scope group, an authorization token that is signed with reciting only scopes in the extent of the authority that the user currently has is issued,

in the authorization server, upon issuing an authorization token corresponding to the scope group, a refresh token for reissuing the authorization token is additionally issued, and

in the authorization server, in a case where a request to reissue the authorization token using the refresh token is accepted, the authorization token is reissued based on the one or a plurality of scopes associated with the scope group when the request to reissue was accepted.

8. The authority delegating system according to claim 7 , wherein in the verification, the resource server verifies whether or not a permitted scope, that the authorization token indicates, indicates an extent in which a provision of the Web service requested in the usage request is permitted.

9. The authority delegating system according to claim 7 , wherein the at least one processor of the resource server executes the instructions stored in the memory of the resource server to further cause the resource server to determine whether to make a request for verification of the authorization token to the authorization server or to perform verification by the resource server.

10. A non-transitory computer-readable medium storing a program for causing a computer to function to:

receive from a client an authorization request in which a scope group, with which one or a plurality of scopes that define an extent for using a Web service are associated, is designated;

present to a user, in a case where one or more scopes among the one or a plurality of scopes associated with the scope group are included in an extent of an authority that the user has, a screen for accepting an authorization operation corresponding to the authorization request;

issue to the client, in accordance with accepting the authorization operation of the user corresponding to the authorization request via the screen, authorization information relating to the scope group; and

issue, in accordance with accepting an authorization token request based on the issued authorization information, an authorization token corresponding to the scope group,

wherein upon issuing an authorization token corresponding to the scope group, an authorization token that is signed with reciting only scopes in the extent of the authority that the user currently has is issued,

upon issuing an authorization token corresponding to the scope group, a refresh token for reissuing the authorization token is additionally issue, and

in a case where a request to reissue the authorization token using the refresh token is accepted, the authorization token is reissued based on the one or a plurality of scopes associated with the scope group when the request to reissue was accepted, and

verification of the authorization token is performed by a resource server for providing a Web service.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 8, 2018
From: MATSUGASHITA, HAYATO
To: CANON KABUSHIKI KAISHA
Reel/Frame 045281/0432 →
Priority Claims (1)
JP 2016-225381 · Nov 18, 2016 · national
Continuity (1)
Related Publication 20180145967A1 · May 24, 2018
Cited By (2)
US 12,513,136 US 12,671,587