Access Right Management via Token-Based Proxy Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing access right management systems face issues with information leakage and inefficiency when a user transfers access rights between service providers, as they exchange unnecessary user information and require setting access rights for multiple providers, leading to increased complexity and security risks.
Innovation Solution
An access right management system that includes an authentication device generating user authentication certificates and right transfer tokens, a service proxy access device requesting and using these tokens for access, and a service providing device verifying access rights using the tokens, thereby reducing unnecessary information exchange and centralizing access control settings.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If service providers exchange user information and access right certificates to enable proxy access, then access right transfer functionality is achieved, but information leakage risk increases and security deteriorates
Solution Approach 1:
The patent extracts only the necessary access right information from the full user certificate and presents it separately through a dedicated access right certificate structure. This allows service providers to obtain only the minimal required information (access right attributes) without receiving unnecessary user personal information, thereby enabling access right transfer while minimizing information leakage risk.
Solution Approach 2:
The access right management system segments the certificate information into separate components: user authentication information remains with the authentication device, while access right attributes are extracted and packaged in a separate access right certificate. This segmentation allows selective disclosure of only the necessary access right information to service providers, reducing the information exposure surface.
2Measurement precision
If users set access rights for multiple service providers individually, then access control precision is improved, but system complexity and operational burden increase
Solution Approach 1:
The access right management device serves as a universal intermediary that handles access right management for multiple service providers through a single centralized system. Instead of users configuring access rights individually with each service provider, the universal access right management device mediates all access right transfers, reducing system complexity while maintaining precise access control through centralized policy management.
Solution Approach 2:
The access right management device acts as an intermediary between users and service providers. It receives access right transfer requests from users, validates them against security policies, and issues access right certificates to service providers. This intermediary role eliminates the need for users to directly configure access rights with multiple service providers, reducing operational complexity while maintaining precise access control.
3Reliability
If service providers verify access rights by exchanging full user certificates, then authentication reliability is improved, but information exchange volume increases and efficiency decreases
Solution Approach 1:
The patent extracts only the essential access right verification information from the full user certificate and packages it in a compact access right certificate. This extracted information contains only the necessary access right attributes needed for verification, significantly reducing the information exchange volume compared to transmitting full user certificates while maintaining authentication reliability.
Solution Approach 2:
Instead of transmitting the original full user certificate, the system creates a copy or derivative (access right certificate) that contains only the necessary access right information. This copied structure maintains the essential verification functionality while being much more efficient in terms of information exchange volume and processing requirements.
Data Source
AI summary
An authentication includes a unit that issues right transfer information that is to be transmitted to a service providing device and a token that corresponds to the right transfer information and is to be transmitted to a service proxy access device on a basis of information about a user to whom a right is transferred and a condition under which the right is transferred, a unit that provides the token to the service proxy access device, and a unit that receives from the service providing device the token transferred from the service proxy access device and transmits to the service providing device the right transfer information that corresponds to the token and is kept by the authentication device.


