Access Token Mediator for Secure Resource Sharing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users face difficulties in managing multiple online accounts and securely sharing information across different services, leading to complex and costly security and data management issues, especially when sharing personal data without exposing it to unauthorized access.

Innovation Solution

A method for customized authentication and access is introduced, where a principal identifier, resource identifier, and access rights are used to create an access token that allows controlled access to resources without requiring the external principal to have an account with the system controlling the resource, utilizing a proxy and social network authentication systems for secure access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If users provide their ID and password to external services for accessing protected resources, then access to resources is enabled, but security risk increases as credentials become vulnerable to compromise

Engineering Contradiction:
Improveaccess to resourcesVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces an access token as an intermediary credential that mediates between the user and external services. Instead of sharing direct credentials (ID and password), the user receives an access token from their identity provider that allows external services to access protected resources without exposing the user's actual credentials. This token acts as a safe intermediary that enables resource access while maintaining security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If administrators move files and resources to isolated systems with controlled public access, then security is improved, but device complexity and operational difficulty increase

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The access token system provides a universal solution that works across multiple services and platforms without requiring isolated systems for each service. The token can be used to access resources across different external services, eliminating the need to create separate controlled environments for each service while maintaining security through standardized authentication.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Adaptability or versatility

If users share personal data with external services, then data sharing capability is improved, but loss of information control and increased liability occur

Engineering Contradiction:
Improvedata sharing capabilityVSAvoidinformation control
Core Design Contradiction:
Adaptability or versatilityVSLoss of information

Solution Approach 1:

The access token system enables dynamic control over data sharing. Users can issue tokens with specific permissions and validity periods, allowing them to control what data is shared, with whom, and for how long. This dynamic control mechanism allows users to adapt their data sharing permissions based on specific needs while maintaining oversight and control over their personal information.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS10270741B2Personal authentication and access
Publication Date: 2019.04.23 MICRO FOCUS LLC
  • US10270741B2 patent drawing
  • US10270741B2 patent drawing
  • US10270741B2 patent drawing

AI summary

A user of a system defines a limited use access token for an external user for that external user to access defined resources of the system based on the user's account with the system. An access control system validates the access token when the external user attempts to access the defined resources and grants the external principal access to the defined resources.