Authorization Certificate Chain for Secure Re-Delegation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Online collaboration is threatened by security issues such as data eavesdropping, data tampering, and entity repudiation, which compromise privacy and identity verification in shared resource environments.

Innovation Solution

A method and system for delegating authority through the creation and verification of authorization certificates, establishing a chain of certificates with re-delegation permissions, and ensuring the validity and operation permissions within the chain, using a Public Key Infrastructure (PKI) for secure access to collaborative resources.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If authorization is delegated through multiple levels in a collaborative environment, then ease of operation and resource sharing are improved, but security risks and complexity of authority verification increase

Engineering Contradiction:
Improveease of resource sharingVSAvoidcomplexity of authority verification
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent segments the authorization verification process into distinct components: certificate issuance, certificate chaining, and verification steps. Each authorization level is represented as a separate certificate in a chain, allowing the system to verify authority by traversing the chain rather than managing complex multi-level permissions centrally. This segmentation reduces verification complexity while enabling easy resource sharing through automated certificate-based authentication.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces authorization certificates as intermediary objects that mediate between resource owners and collaborators. These certificates act as trusted intermediaries that carry authorization information through the system, eliminating the need for direct complex verification between all parties. The certificate chain serves as an intermediary structure that simplifies multi-level authorization verification.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If re-delegation permissions are allowed in authorization chains, then adaptability and flexibility of access control are improved, but security risks and potential for unauthorized access increase

Engineering Contradiction:
Improveflexibility of access controlVSAvoidsecurity of access control
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent applies preliminary action by embedding re-delegation permissions and constraints directly into the authorization certificate during its creation. The certificate contains pre-defined rules about whether re-delegation is allowed and under what conditions. This preliminary configuration ensures that re-delegation follows security policies from the outset, providing flexibility while maintaining security through pre-established constraints rather than ad-hoc decisions.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The verification process incorporates feedback by checking each certificate in the chain against security policies and verifying that re-delegation permissions are properly maintained. The system provides feedback by validating whether each re-delegation step complies with the original authorization constraints, ensuring security is maintained even as flexibility is provided through multiple delegation levels.

Inventive Principle:
Principle #23Feedback

3Reliability

If comprehensive verification of authorization chains is performed, then reliability and security of access control are improved, but processing time and system complexity increase

Engineering Contradiction:
Improvesecurity of access controlVSAvoidprocessing time for verification
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies preliminary action by having authorization certificates pre-signed and pre-validated by trusted authorities before being issued to users. The certificates contain pre-computed cryptographic signatures and validation data that enable rapid verification. This preliminary preparation reduces the time required for comprehensive verification during actual access control decisions, as the heavy validation work has already been performed during certificate issuance.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS7546463B2Method and system for delegating authority in an online collaborative environment
Publication Date: 2009.06.09 SAP SE
  • US7546463B2 patent drawing
  • US7546463B2 patent drawing
  • US7546463B2 patent drawing

AI summary

A method and system to delegate an authority to access collaborative resources are provided. The system enables a participant to re-delegate the authority to another participant by an authorization certificate. A chain of authorization certificates is established along with the re-delegation of the authority from one participant to another. The participant requesting access to the collaborative resources is requested to provide the owner with the chain of authorization certificates for verification. Therefore, the re-delegation process may be performed without the need to notify the owner and yet without comprising the security of the collaborative resources.