Service Access Authorization Provider Grace Period Mechanism

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Digital rights management systems and access authorization systems face challenges in efficiently managing service access authorizations, particularly in ensuring that user identifiers are not reused prematurely and that users whose subscriptions have expired are prevented from accessing content without receiving extension messages, leading to operational inconvenience and potential exclusion from service usage.

Innovation Solution

A device and method for controlling service access authorization that sets a predetermined duration for service access authorization validity, disabling extensions or reactivations using previous user identifiers if the duration since the last authorization exceeds a predetermined threshold, and managing user identifiers to prevent reuse until the expiration of this duration, thereby optimizing user identification and addressing space.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Quantity of substance

If user identifiers are reused after expiration, then address space is reduced and bandwidth is saved, but unauthorized access may occur and user satisfaction deteriorates

Engineering Contradiction:
Improvenumber of user identifiersVSAvoidaccess authorization security
Core Design Contradiction:
Quantity of substanceVSReliability

Solution Approach 1:

The system implements a grace period mechanism that preliminarily maintains authorization status after expiration before allowing identifier reuse. This prevents immediate access denial while still enabling security control, resolving the contradiction between reducing identifier quantity and maintaining access security.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The grace period acts as an intermediary mechanism between authorization expiration and identifier reuse. It provides a transition phase that allows the system to safely reduce the number of active identifiers while preventing unauthorized access, thus balancing security and resource efficiency.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If user identifiers are not reused, then access security is maintained, but bandwidth consumption increases and address space is wasted

Engineering Contradiction:
Improveaccess authorization securityVSAvoidbandwidth consumption
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The system changes the temporal parameter of identifier validity by introducing a grace period that extends the effective usage window. This allows identifiers to be reused after a controlled delay, reducing the total number of identifiers needed and thereby reducing bandwidth consumption while maintaining security through the time-based constraint.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If authorization is immediately denied after expiration, then security is maintained, but user satisfaction decreases due to operational inconvenience

Engineering Contradiction:
Improveaccess authorization securityVSAvoiduser access convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The grace period provides a preliminary缓冲 period before strict access denial takes effect. This allows users who may have experienced temporary disconnection or processing delays to regain access without compromising security, thus improving ease of operation while maintaining authorization integrity.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The grace period acts as a cushioning mechanism that softens the impact of authorization expiration. It provides a buffer zone that prevents immediate and harsh access denial, thereby improving user experience while still enforcing security through the limited time window.

Inventive Principle:
Principle #11Beforehand cushioning (Prior cushioning)

Data Source

PatentUS9165121B2Concept of efficiently distributing access authorization information
Publication Date: 2015.10.20 FRAUNHOFER GESELLSCHAFT ZUR FORDERUNG DER ANGEWANDTEN FORSCHUNG EV
  • US9165121B2 patent drawing
  • US9165121B2 patent drawing
  • US9165121B2 patent drawing

AI summary

A device for controlling a service access authorization for a user device with regard to an access-restricted service includes a service access authorization provider, the service access authorization provider being configured to set a period of time in which the service access authorization is valid, responsive to an authorization message provided with a service-dependent user identifier, and the service access authorization provider being configured to disable an authorization allowing the service access authorization to be extended or reactivated using the previous service-dependent user identifier when at least a predetermined duration has passed since an end of a last authorization time interval for which a service access authorization was determined by the device.