Authorization Certificate Administration via Intermediary Batching
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In device-to-device computing environments, devices often face challenges in obtaining authorization for services or actions without persistent connectivity to an infrastructure portal, especially when they cannot directly connect to a signing authority.
Innovation Solution
A method where an administration device collects and forwards authorization requests to a signing authority, generating certificates that encode permissions, which can be delivered using different communication paths, allowing devices to obtain necessary permissions even without a secure connection to the infrastructure.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If devices directly connect to signing authority for authorization, then security and reliability are improved, but device complexity and infrastructure dependency increase
Solution Approach 1:
The patent introduces an administration device as an intermediary between requesting devices and the signing authority. The administration device collects authorization requests from multiple devices, forwards them to the signing authority, and distributes the generated certificates back to the requesting devices. This intermediary approach maintains security through centralized certificate issuance while reducing infrastructure complexity by allowing devices to connect through available communication paths rather than requiring direct connections to the signing authority.
2Productivity
If devices maintain persistent connection to infrastructure portal, then authorization efficiency is improved, but loss of time and energy for connection maintenance increase
Solution Approach 1:
The system performs preliminary actions by having the administration device collect and batch multiple authorization requests before forwarding them to the signing authority. This batch processing approach eliminates the need for each device to maintain persistent connections or make individual real-time requests, thereby improving authorization efficiency while reducing the time and energy spent on connection maintenance.
Solution Approach 2:
The administration device periodically collects authorization requests from devices and batches them for processing. This periodic batch processing replaces continuous persistent connections, allowing devices to obtain authorizations efficiently without maintaining constant infrastructure connections, thus reducing time and energy loss.
3Measurement precision
If multiple devices request authorization individually, then authorization precision is improved, but loss of time and infrastructure dependency increase
Solution Approach 1:
The patent merges multiple individual authorization requests into a single batched request processed by the administration device. Each device's specific authorization needs are preserved and individually validated by the signing authority, maintaining authorization precision. However, by combining the communication overhead into a single transaction, the system dramatically reduces the total time required and eliminates the need for multiple separate infrastructure connections.
Data Source
AI summary
A method for providing a set of certificates encoding authorisations, the method comprising processing respective ones of multiple authorisation requests at a trusted signing authority apparatus to verify respective digital signatures applied to the requests, the multiple authorisation requests received over a first communication link between the trusted signing authority apparatus and an administration apparatus, validating one or more authorisation request parameters of respective ones of the authorisation requests, generating a certificate encoding an authorisation at the trusted signing authority apparatus and transmitting the generated certificate to the administration apparatus or a requesting apparatus over a second communication link.

