Authorization Server Application License Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing solutions fail to effectively control and authorize the use of software applications on personal devices connecting to enterprise networks, as they either rely on port blocking or limited client software deployment, which do not address software upgrades or personal licenses.
Innovation Solution
A method involving an authorization server and an auxiliary license server that identifies applications requiring enterprise licenses, requests and books upgrades, and authorizes their use only when valid licenses are available, ensuring compliance with enterprise software rules.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If port blocking is used to control unauthorized applications, then network security is improved, but the control effectiveness deteriorates because many applications use standard ports like 8080
Solution Approach 1:
The patent introduces an authorization server as an intermediary between the network and user devices. This server dynamically identifies applications requiring enterprise licenses and manages their authorization status, providing effective control beyond simple port blocking by mediating at the application level rather than the network protocol level
Solution Approach 2:
The system implements dynamic control where the authorization server continuously monitors and updates the status of applications based on license availability and user actions. The control mechanism adapts in real-time rather than using static port blocking rules, allowing the system to respond to changing conditions such as license upgrades and application installations
2Ease of operation
If control client software is deployed in each user device to forbid installation of unauthorized applications, then application control is improved, but user acceptance deteriorates because users reject blocking of personal applications they need
Solution Approach 1:
The system allows users to self-manage their application licensing by viewing which applications require enterprise licenses and performing license upgrades directly from their devices. The authorization server provides users with the ability to request and manage their own license upgrades, transforming a restrictive control mechanism into an empowering self-service system
Solution Approach 2:
Instead of blocking applications and requiring users to work around restrictions, the system inverts the approach by allowing applications to run freely while providing users with the option to upgrade licenses for enhanced functionality. The control mechanism becomes optional rather than mandatory, improving user acceptance while maintaining enterprise compliance
3Reliability
If personal applications are blocked without enterprise licenses, then enterprise compliance is improved, but productivity deteriorates because users cannot access needed applications
Solution Approach 1:
The system performs preliminary identification of applications that may require enterprise licenses before they are blocked. The authorization server proactively notifies users of applications needing license upgrades and facilitates the upgrade process before productivity is impacted, rather than waiting for compliance violations to occur
Solution Approach 2:
The system implements continuous feedback loops where the authorization server monitors application usage, identifies licensing requirements, and communicates with users about upgrade opportunities. This feedback mechanism ensures users are informed about compliance requirements while maintaining access to needed applications through the upgrade process
Data Source
Figure 1~2
Figure 3~4
AI summary
A method is provided for controlling the use of applications running on items of communication equipment (21-24), belonging to users having access to a private network (1) comprising a licence server (3) arranged for managing the licences of applications that are authorized to be used by these items of user communication equipment (21-24), when they are connected to this private network (1). This method comprises a step during which, when an item of user communication equipment (21) has established a connection with the private network (1), the use of each application of this user communication equipment is forbidden (21), after which it is determined in an authorization server (4) of the private network (1) the applications of this user communication equipment (21) that are authorized to be used by the latter (1), after which the use is authorized by this user communication equipment (21) of the applications authorized by the authorization server (4).