Access Token Mediator for Secure Resource Sharing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Users face difficulties in managing multiple online accounts and securely sharing information across different services, leading to complex and costly security and data management issues, especially when sharing personal data without exposing it to unauthorized access.
Innovation Solution
A method for customized authentication and access is introduced, where a principal identifier, resource identifier, and access rights are used to create an access token that allows controlled access to resources without requiring the external principal to have an account with the system controlling the resource, utilizing a proxy and social network authentication systems for secure access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If users provide their ID and password to external services for accessing protected resources, then access to resources is enabled, but security risk increases as credentials become vulnerable to compromise
Solution Approach 1:
The patent introduces an access token as an intermediary credential that mediates between the user and external services. Instead of sharing direct credentials (ID and password), the user receives an access token from their identity provider that allows external services to access protected resources without exposing the user's actual credentials. This token acts as a safe intermediary that enables resource access while maintaining security.
2Reliability
If administrators move files and resources to isolated systems with controlled public access, then security is improved, but device complexity and operational difficulty increase
Solution Approach 1:
The access token system provides a universal solution that works across multiple services and platforms without requiring isolated systems for each service. The token can be used to access resources across different external services, eliminating the need to create separate controlled environments for each service while maintaining security through standardized authentication.
3Adaptability or versatility
If users share personal data with external services, then data sharing capability is improved, but loss of information control and increased liability occur
Solution Approach 1:
The access token system enables dynamic control over data sharing. Users can issue tokens with specific permissions and validity periods, allowing them to control what data is shared, with whom, and for how long. This dynamic control mechanism allows users to adapt their data sharing permissions based on specific needs while maintaining oversight and control over their personal information.
Data Source
AI summary
A user of a system defines a limited use access token for an external user for that external user to access defined resources of the system based on the user's account with the system. An access control system validates the access token when the external user attempts to access the defined resources and grants the external principal access to the defined resources.


