Authorization Server Mediator for Remote Resource Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current application management solutions fail to adequately address the unique security concerns for authorizing access to remote resources, particularly for sensitive data like medical or financial records, by not providing sufficient control over user devices and compliance with stringent authorization rules.

Innovation Solution

A system and method that determine whether a user device is authorized to access remote resources based on the issuance of a management identifier and compliance with specified rules, ensuring secure access by managing user device permissions and enforcing compliance through a management service and resource server interaction.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional authorization methods are used, then basic access control is provided, but security for sensitive resources is insufficient

Engineering Contradiction:
ImprovesecurityVSAvoidauthorization system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an authorization server as an intermediary component that mediates between resource servers and client devices. This server evaluates authorization requests against stored authorization rules and returns authorization tokens, thereby enhancing security without requiring complex authorization logic to be distributed across all system components.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The authorization system is segmented into distinct functional components: resource servers that host data, client devices that make requests, and an authorization server that evaluates requests against authorization rules. This segmentation allows each component to have a specific, simplified function while the system as a whole provides comprehensive security.

Inventive Principle:
Principle #1Segmentation

2Reliability

If simple user authentication is used, then ease of access is maintained, but control over user device security is insufficient

Engineering Contradiction:
Improvedevice security controlVSAvoidaccess convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system performs preliminary evaluation of authorization requests against authorization rules before granting access. The authorization server assesses device security posture, user credentials, and contextual factors in advance, and only then issues authorization tokens. This preliminary action ensures device security control is established before access is permitted.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If comprehensive authorization rules are implemented, then security for sensitive resources is enhanced, but system complexity increases

Engineering Contradiction:
Improveresource protectionVSAvoidauthorization management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authorization server acts as an intermediary that manages comprehensive authorization rules centrally. It stores, evaluates, and enforces authorization policies without requiring resource servers or client devices to implement complex authorization logic locally, thereby maintaining resource protection while reducing distributed system complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Productivity

If manual authorization management is used, then flexibility is maintained, but productivity is reduced

Engineering Contradiction:
Improveauthorization efficiencyVSAvoidmanual management effort
Core Design Contradiction:
ProductivityVSEase of operation

Solution Approach 1:

The authorization system operates autonomously by automatically evaluating authorization requests against stored rules and issuing or denying authorization tokens without manual intervention. This self-service mechanism enhances productivity by eliminating manual authorization management while maintaining flexibility through rule-based decision-making.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11570160B2Securely authorizing access to remote resources
Publication Date: 2023.01.31 OMNISSA LLC
  • US11570160B2 patent drawing
  • US11570160B2 patent drawing
  • US11570160B2 patent drawing

AI summary

Methods and an apparatus are provided for securely authorizing access to remote resources. For example, a method is provided that includes receiving a request to determine whether a user device communicatively coupled to a resource server is authorized to access at least one resource hosted by the resource server and determining whether the user device communicatively coupled to the resource server is authorized to access the at least one resource hosted by the resource server based at least in part on whether the user device communicatively coupled to the resource server has been issued a management identifier. The method further includes providing a response indicating that the user device communicatively coupled to the resource server is authorized to access the at least one resource hosted by the resource server in response to a determination that the user device communicatively coupled to the resource server is authorized to access the at least one resource hosted by the resource server. The method yet further includes providing a response indicating that the user device communicatively coupled to the resource server is not authorized to access the at least one resource hosted by the resource server in response to a determination that the user device communicatively coupled to the resource server is not authorized to access the at least one resource hosted by the resource server.