Authorization Service Mediates Cloud Resource Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cloud-based network environments lack the configurability and customization needed to effectively manage access to enterprise resources at a device level, posing challenges in protecting sensitive information and services.

Innovation Solution

A system where a client-side application on a client device requests authorization from an authorization service, which authenticates user credentials and device identifiers, and requires a key application to be installed and enabled on the device to access resources, using distribution rules to ensure compliance before granting access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If cloud-based network environments are used to host enterprise resources, then accessibility and scalability are improved, but security control and device-level access management deteriorate

Engineering Contradiction:
ImproveaccessibilityVSAvoidsecurity control
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces an authorization service as an intermediary between cloud-based enterprise resources and client devices. This service mediates access requests by authenticating user credentials and device identifiers, then determining whether to grant access based on distribution rules. The intermediary handles security control centrally while allowing cloud resources to remain accessible, resolving the contradiction between accessibility and security control.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If traditional access control methods (firewalls, VPNs) are used in cloud environments, then network-level security is maintained, but device-level access management capability deteriorates

Engineering Contradiction:
Improvenetwork securityVSAvoiddevice-level management
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments access control into multiple levels: network-level controls (firewalls, VPNs) and device-level controls (authorization service checking device identifiers and compliance with distribution rules). This segmentation allows both network security and device-level management to coexist, with each layer handling appropriate security functions independently.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent adds a new dimension of control by moving from purely network-level security to include device-level security attributes. The authorization service evaluates device identifiers, compliance status, and distribution rules as additional dimensions of access control, enabling fine-grained device-level management while maintaining network security boundaries.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Adaptability or versatility

If cloud-based data services are used, then resource accessibility is improved, but device-level access management configurability deteriorates

Engineering Contradiction:
Improveresource accessibilityVSAvoiddevice-level management configurability
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent implements dynamic distribution rules that can be configured and modified by enterprises based on their specific security requirements. The authorization service evaluates these rules in real-time against device identifiers and compliance status, allowing flexible device-level management configuration while maintaining cloud-based resource accessibility. Rules can be adjusted without changing the underlying cloud infrastructure.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS11689516B2Application program as key for authorizing access to resources
Publication Date: 2023.06.27 OMNISSA LLC
  • US11689516B2 patent drawing
  • US11689516B2 patent drawing
  • US11689516B2 patent drawing

AI summary

In a networked environment, an application executed on a computing device may transmit a distribution rule associated with a resource. The distribution rule can require a key application to be enabled as hardware associated with a client device prior to access to a resource. The application may receive a request for access to the resource by the client device. In an instance in which it is determined that the client device complies with the distribution rule, the application may provide, to the client device, authorization to access the resource.