Authorization Server Emulation for Secure Cross-Domain Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Customers of large organizations often face difficulties accessing specific portions of a website due to browser settings or security segregation, making it hard for customer care representatives to replicate and resolve user-experienced problems.

Innovation Solution

A system that allows a first client device, typically used by a care representative, to emulate a second client device associated with a different domain by providing a generic login and session cookies, enabling limited access to resources and tools within the second domain for troubleshooting and problem resolution.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If browser settings are adjusted to access restricted portions of a website, then access to targeted information is improved, but security control and domain isolation are worsened

Engineering Contradiction:
Improveaccess to website portionsVSAvoidsecurity control
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces an authorization server as an intermediary between the first client device and the second domain. This server mediates the access by verifying authentication tokens, checking emulation authorization against permitted emulation files, and creating session cookies that enable controlled access without compromising the security architecture of either domain.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system changes the access parameters by transitioning from direct domain access to cookie-based session management. The authorization server creates session cookies with specific parameters (domain restrictions, path limitations, expiration times) that dynamically control access levels, allowing the first client device to access specific portions of the second domain while maintaining security boundaries.

Inventive Principle:
Principle #35Parameter changes

2Productivity

If a first client device emulates a second client device to access restricted resources, then problem diagnosis capability is improved, but system complexity and authorization management are worsened

Engineering Contradiction:
Improveproblem diagnosis capabilityVSAvoidauthorization management
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent implements a copying mechanism where the first client device creates a copy of the second client device's identity and session characteristics through emulation. The authorization server verifies this copying by checking authentication tokens and creating session cookies that replicate the necessary access parameters without requiring full system duplication or complex manual configuration.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The system performs preliminary actions by pre-defining permitted emulations in files maintained by the authorization server. These files contain advance authorization rules that specify which first client devices can emulate which second client devices and under what conditions. This preliminary configuration simplifies runtime authorization management by replacing complex real-time decisions with pre-established rules.

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If generic login accounts are used for cross-domain access, then ease of access is improved, but access precision and user-specific customization are worsened

Engineering Contradiction:
Improvecross-domain accessVSAvoidaccess precision
Core Design Contradiction:
Ease of operationVSMeasurement precision

Solution Approach 1:

The patent applies local quality by creating session cookies with domain-specific and path-specific attributes. Each cookie is tailored to the particular second domain and specific portions of that domain that the first client device needs to access. This localized approach allows generic login accounts to provide precise, context-appropriate access rather than blanket access or no access at all.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system introduces dynamics through session cookies that are created temporarily for each emulation request and automatically expire after use. The access rights are not static but dynamically granted and revoked based on the specific emulation needs. This dynamic approach allows the system to provide precise access control while maintaining the simplicity of generic login accounts, as the precision is achieved through temporary, context-specific session management rather than permanent user-specific configurations.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS8875243B1Identity abstraction providing limited cross-domain access
Publication Date: 2014.10.28 T MOBILE INNOVATIONS LLC
  • US8875243B1 patent drawing
  • US8875243B1 patent drawing
  • US8875243B1 patent drawing

AI summary

A system is provided. The system comprises a processor, a memory, and an authorization application stored in the memory that, when executed by the processor, receives a first message from a first client device associated with a first domain, the first message containing a request to emulate a second client device associated with a second domain. The system also determines authorization for the first device to emulate the second device in the second domain. The system also associates an electronic cookie with a browser session initiated by the first device, the electronic cookie associated with access to the second domain. The system also provides the first device authorization to emulate the second device in the second domain using a generic login account wherein the second domain provides the first device limited cross-domain access based on the electronic cookie to targeted information associated with the second device.