Access Relationship Management via Intermediate Entity Routing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Managing complex and unintended access relationships in large computing environments is challenging due to the creation of long, complicated chains of trust that can lose their original purpose, leading to difficulties in monitoring and controlling access permissions across numerous entities.

Innovation Solution

A method and apparatus for determining and managing access relationships by creating a chain of access relationships between entities, allowing for the selection of intermediate entities to route access relationships, and prioritizing or replacing existing relationships based on various criteria such as security credentials, policy, and data traffic, enabling better control and visibility of access permissions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If access relationships are managed through multiple intermediate entities forming chains of trust, then access control flexibility and granularity are improved, but system complexity and difficulty in monitoring increase

Engineering Contradiction:
Improveaccess control flexibilityVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary entity (the system performing the method) that manages and coordinates access relationships between multiple entities. This intermediary consolidates the complexity of managing chained trust relationships by providing a centralized mechanism to determine, select, and create access relationships, thereby maintaining flexibility while reducing overall system complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the complex access relationship management into distinct operational steps: determining existing relationships, selecting intermediate entities, and creating new relationships. This segmentation allows each component to be managed independently, improving flexibility while making the overall system more manageable and less complex.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If long and complicated chains of trust are created between entities, then access routing options increase, but monitoring and controlling access permissions becomes more difficult

Engineering Contradiction:
Improveaccess routing optionsVSAvoidmonitoring difficulty
Core Design Contradiction:
Adaptability or versatilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent implements a feedback mechanism where the system continuously determines existing access relationships and evaluates them against selection criteria. This feedback loop enables the system to monitor and control access permissions effectively by assessing the current state and making informed decisions about creating or modifying access relationships, thereby reducing monitoring difficulty while maintaining routing flexibility.

Inventive Principle:
Principle #23Feedback

3Adaptability or versatility

If multiple access relationships are maintained between entities, then access control granularity is improved, but administrative overhead increases

Engineering Contradiction:
Improveaccess control granularityVSAvoidadministrative overhead
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The patent enables the system to automatically manage access relationships by autonomously determining existing relationships, selecting appropriate intermediate entities based on predefined criteria, and creating new relationships without manual intervention. This self-service approach maintains fine-grained access control while significantly reducing administrative overhead and time loss.

Inventive Principle:
Principle #25Self-service

4Adaptability or versatility

If access relationships are allowed to evolve independently without coordination, then entity autonomy is maintained, but unintended access chains are created

Engineering Contradiction:
Improveentity autonomyVSAvoidaccess relationship integrity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent applies preliminary action by establishing coordination mechanisms before access relationships evolve independently. The system determines existing relationships and selects intermediate entities based on predefined selection criteria before creating new relationships, ensuring that access chains are intentionally designed rather than accidentally formed, thereby maintaining both entity autonomy and relationship integrity.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP3343841B1Access relationships in a computer system
Publication Date: 2020.10.21 SSH COMMUNICATIONS SECURITY
  • EP3343841B1 patent drawingFigure 1
  • EP3343841B1 patent drawingFigure 2~3
  • EP3343841B1 patent drawingFigure 4

AI summary

The disclosure relates to access relationships, more particularly to controlling access relationships between entities in a computerized system. In the disclose arrangement a first access relationship between a first entity and a second entity is determined. At least one intermediate entity is selected for routing of a second access relationship between the first entity and the second entity via the at least one intermediate entity. The second access relationship is created, the second access relationship comprising a chain of access relationships via the first entity, the at least one intermediate entity and the second entity.