US2013031612A1PendingUtilityA1

Server apparatus, information processing method, program, and storage medium

Assignee: CANON KKPriority: Jul 28, 2011Filed: Jul 23, 2012Published: Jan 31, 2013
Est. expiryJul 28, 2031(~5 yrs left)· nominal 20-yr term from priority
H04L 63/105G06F 21/335H04L 63/083H04L 63/10H04L 63/102H04L 12/14H04L 63/101H04L 2463/101
43
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

An information processing method for a server apparatus controlling access based on a role of a user and a scope as authority held by an authorization token for realizing a unified license management structure that does not reduce an overall performance of a cloud service even if a plurality of services collaborate with the cloud service.

Claims

exact text as granted — not AI-modified
1 . A server apparatus comprising:
 an acquisition unit configured to, when authorization information including token identification information of an authorization token and a received scope as authority of the authorization token is received, reference token data comprising the token identification information, the scope, and user identification information based on the token identification information, and acquire the scope and the user identification information linked to the token identification information included in the authorization information;   a determination unit configured to, if identification information used for identifying a cloud service is set in the scope acquired by the acquisition unit, determine whether the cloud service identified by the identification information is defined in the received scope included in the authorization information;   a service use non-permission unit configured to, if the determination unit determines that the cloud service identified by the identification information is not defined in the received scope included in the authorization information, not permit use of the cloud service identified by the identification information;   a service availability determination information acquisition unit configured to, if the determination unit determines that the cloud service identified by the identification information is defined in the received scope included in the authorization information, reference role reference data that the scope and information of whether the role as authority for a user to access the cloud service needs to be referenced are linked, based on the received scope included in the authorization information, and acquire service availability determination information indicating whether a role linked to the received scope included in the authorization information needs to be referenced; and   a service use permission unit configured to permit use of the cloud service identified by the identification information if the service availability determination information acquired by the service availability determination information acquisition unit indicates that referencing the role is not necessary.   
     
     
         2 . The server apparatus according to  claim 1 , further comprising:
 a role acquisition unit configured to, if identification information used for identifying the cloud service is not set in the scope acquired by the acquisition unit, acquire the role linked to the user identification information acquired by the acquisition unit, wherein user management data including the role as authority for a user to access the cloud service,   wherein the service use permission unit further permits use of the cloud service if the user has the authority to access the cloud service defined in the received scope included in the authorization information, based on the role acquired by the role acquisition unit.   
     
     
         3 . The server apparatus according to  claim 2 , wherein if the authority for accessing the cloud service defined in the received scope included in the authorization information is not assigned to the role acquired by the role acquisition unit, the service use non-permission unit further does not permit use of the cloud service. 
     
     
         4 . The server apparatus according to  claim 2 , wherein if the service availability determination information acquired by the service availability determination information acquisition unit indicates that the role needs to be referenced, the role acquisition unit references the user management data based on the user identification information acquired by the acquisition unit, and further acquires the role linked to the user identification information acquired by the acquisition unit. 
     
     
         5 . The server apparatus according to  claim 2 , further comprising a user management unit configured to manage the user management data, wherein the user management unit assigns a role to a paying user and does not assign a role to a non-paying user when registering data to the user management data. 
     
     
         6 . The server apparatus according to  claim 1 , further comprising an authorization token issuance unit configured to issue the authorization token, wherein when registering data in the token data, the authorization token issuance unit does not set the identification information used for identifying the cloud service to the scope with respect to a paying user and sets the identification information used for identifying the cloud service to the scope with respect to a non-paying user. 
     
     
         7 . An information processing method executed by a server apparatus, the method comprising:
 when authorization information including token identification information of an authorization token and a received scope as authority of the authorization token is received, referencing (S 1401 ) token data comprising the token identification information, the scope, and user identification information based on the token identification information, and acquiring (s 1401 ) the scope and the user identification information linked to the token identification information included in the authorization information;   if identification information used for identifying a cloud service is set in the acquired scope, determining (S 1403 ) whether the cloud service identified by the identification information is defined in the received scope included in the authorization information;   if the cloud service identified by the identification information is determined as not defined in the received scope included in the authorization information, permitting no use of the cloud service identified by the identification information (S 1409 );   if the cloud service identified by the identification information is determined as defined in the received scope included in the authorization information, referencing (S 1404 ) role reference data that the scope and information of whether the role as authority for a user to access the cloud service needs to be referenced are linked, based on the received scope included in the authorization information, and acquiring service availability determination information indicating whether a role linked to the received scope included in the authorization information needs to be referenced; and   if the service availability determination information which has been acquired indicates that referencing the role is not necessary, permitting use of the cloud service identified by the identification information (S 1408 ).   
     
     
         8 . The information processing method according to  claim 7 , further comprising:
 if identification information used for identifying the cloud service is not set in the acquired scope, acquiring the acquired role linked to the user identification information, wherein user management data including the role as authority for a user to access the cloud service,   wherein use of the cloud service is further permitted if the user has the authority to access the cloud service defined in the received scope included in the authorization information, based on the acquired role.   
     
     
         9 . The information processing method according to  claim 8 , wherein if the authority for accessing the cloud service defined in the received scope included in the authorization information is not assigned to the acquired role, use of the cloud service is not permitted. 
     
     
         10 . The information processing method according to  claim 8 , further comprising: if the service availability determination information which has been acquired indicates that the role needs to be referenced, referencing (S 1406 ) the user management data based on the user identification information which has been acquired; and acquiring the role linked to the acquired user identification information. 
     
     
         11 . The information processing method according to  claim 8 , further comprising managing the user management data, and assigning a role to a paying user and not assigning a role to a non-paying user when data is registered in the user management data. 
     
     
         12 . The information processing method according to  claim 7 , further comprising issuing the authorization token, wherein when registering data in the token data, the identification information used for identifying the cloud service is not set to the scope with respect to a paying user and is set to the scope with respect to a non-paying user. 
     
     
         13 . A program which, when executed by a computer, causes the computer to carry out the method of  claim 7 . 
     
     
         14 . A computer-readable storage medium storing the computer program according to  claim 13 .

Join the waitlist — get patent alerts

Track US2013031612A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.