Access Right Management via Token-Based Proxy Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing access right management systems face issues with information leakage and inefficiency when a user transfers access rights between service providers, as they exchange unnecessary user information and require setting access rights for multiple providers, leading to increased complexity and security risks.

Innovation Solution

An access right management system that includes an authentication device generating user authentication certificates and right transfer tokens, a service proxy access device requesting and using these tokens for access, and a service providing device verifying access rights using the tokens, thereby reducing unnecessary information exchange and centralizing access control settings.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If service providers exchange user information and access right certificates to enable proxy access, then access right transfer functionality is achieved, but information leakage risk increases and security deteriorates

Engineering Contradiction:
Improveaccess right transfer functionalityVSAvoidinformation leakage risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts only the necessary access right information from the full user certificate and presents it separately through a dedicated access right certificate structure. This allows service providers to obtain only the minimal required information (access right attributes) without receiving unnecessary user personal information, thereby enabling access right transfer while minimizing information leakage risk.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The access right management system segments the certificate information into separate components: user authentication information remains with the authentication device, while access right attributes are extracted and packaged in a separate access right certificate. This segmentation allows selective disclosure of only the necessary access right information to service providers, reducing the information exposure surface.

Inventive Principle:
Principle #1Segmentation

2Measurement precision

If users set access rights for multiple service providers individually, then access control precision is improved, but system complexity and operational burden increase

Engineering Contradiction:
Improveaccess control precisionVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The access right management device serves as a universal intermediary that handles access right management for multiple service providers through a single centralized system. Instead of users configuring access rights individually with each service provider, the universal access right management device mediates all access right transfers, reducing system complexity while maintaining precise access control through centralized policy management.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The access right management device acts as an intermediary between users and service providers. It receives access right transfer requests from users, validates them against security policies, and issues access right certificates to service providers. This intermediary role eliminates the need for users to directly configure access rights with multiple service providers, reducing operational complexity while maintaining precise access control.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If service providers verify access rights by exchanging full user certificates, then authentication reliability is improved, but information exchange volume increases and efficiency decreases

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidaccess right transfer efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent extracts only the essential access right verification information from the full user certificate and packages it in a compact access right certificate. This extracted information contains only the necessary access right attributes needed for verification, significantly reducing the information exchange volume compared to transmitting full user certificates while maintaining authentication reliability.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

Instead of transmitting the original full user certificate, the system creates a copy or derivative (access right certificate) that contains only the necessary access right information. This copied structure maintains the essential verification functionality while being much more efficient in terms of information exchange volume and processing requirements.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS8935747B2Access right management system, access right management method, and access right management program
Publication Date: 2015.01.13 NEC CORP
  • US8935747B2 patent drawing
  • US8935747B2 patent drawing
  • US8935747B2 patent drawing

AI summary

An authentication includes a unit that issues right transfer information that is to be transmitted to a service providing device and a token that corresponds to the right transfer information and is to be transmitted to a service proxy access device on a basis of information about a user to whom a right is transferred and a condition under which the right is transferred, a unit that provides the token to the service proxy access device, and a unit that receives from the service providing device the token transferred from the service proxy access device and transmits to the service providing device the right transfer information that corresponds to the token and is kept by the authentication device.