Authorization Server Mediator for Remote Resource Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current application management solutions fail to adequately address the unique security concerns for authorizing access to remote resources, particularly for sensitive data like medical or financial records, by not providing sufficient control over user devices and compliance with stringent authorization rules.
Innovation Solution
A system and method that determine whether a user device is authorized to access remote resources based on the issuance of a management identifier and compliance with specified rules, ensuring secure access by managing user device permissions and enforcing compliance through a management service and resource server interaction.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional authorization methods are used, then basic access control is provided, but security for sensitive resources is insufficient
Solution Approach 1:
The patent introduces an authorization server as an intermediary component that mediates between resource servers and client devices. This server evaluates authorization requests against stored authorization rules and returns authorization tokens, thereby enhancing security without requiring complex authorization logic to be distributed across all system components.
Solution Approach 2:
The authorization system is segmented into distinct functional components: resource servers that host data, client devices that make requests, and an authorization server that evaluates requests against authorization rules. This segmentation allows each component to have a specific, simplified function while the system as a whole provides comprehensive security.
2Reliability
If simple user authentication is used, then ease of access is maintained, but control over user device security is insufficient
Solution Approach 1:
The system performs preliminary evaluation of authorization requests against authorization rules before granting access. The authorization server assesses device security posture, user credentials, and contextual factors in advance, and only then issues authorization tokens. This preliminary action ensures device security control is established before access is permitted.
3Reliability
If comprehensive authorization rules are implemented, then security for sensitive resources is enhanced, but system complexity increases
Solution Approach 1:
The authorization server acts as an intermediary that manages comprehensive authorization rules centrally. It stores, evaluates, and enforces authorization policies without requiring resource servers or client devices to implement complex authorization logic locally, thereby maintaining resource protection while reducing distributed system complexity.
4Productivity
If manual authorization management is used, then flexibility is maintained, but productivity is reduced
Solution Approach 1:
The authorization system operates autonomously by automatically evaluating authorization requests against stored rules and issuing or denying authorization tokens without manual intervention. This self-service mechanism enhances productivity by eliminating manual authorization management while maintaining flexibility through rule-based decision-making.
Data Source
AI summary
Methods and an apparatus are provided for securely authorizing access to remote resources. For example, a method is provided that includes receiving a request to determine whether a user device communicatively coupled to a resource server is authorized to access at least one resource hosted by the resource server and determining whether the user device communicatively coupled to the resource server is authorized to access the at least one resource hosted by the resource server based at least in part on whether the user device communicatively coupled to the resource server has been issued a management identifier. The method further includes providing a response indicating that the user device communicatively coupled to the resource server is authorized to access the at least one resource hosted by the resource server in response to a determination that the user device communicatively coupled to the resource server is authorized to access the at least one resource hosted by the resource server. The method yet further includes providing a response indicating that the user device communicatively coupled to the resource server is not authorized to access the at least one resource hosted by the resource server in response to a determination that the user device communicatively coupled to the resource server is not authorized to access the at least one resource hosted by the resource server.


