Authorization Service for Device-Level Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cloud-based network environments lack the configurability and customization necessary to effectively manage access to enterprise resources at a device level, posing challenges in protecting sensitive information and services.

Innovation Solution

A system and method where a client device communicates with an authorization service to authenticate user and device credentials, and may require a secondary client device to be in communication as a prerequisite for accessing resources, using authorization credentials like PINs, keys, or tokens to ensure secure access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If cloud-based network environments are used to host enterprise resources, then accessibility and scalability are improved, but security and configurability for device-level access control deteriorate

Engineering Contradiction:
ImproveaccessibilityVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces an authorization service as an intermediary between client devices and enterprise resources in the cloud. This service receives access requests, authenticates credentials, verifies distribution rules, and grants or denies access accordingly. The intermediary handles the security complexity centrally, allowing cloud-based accessibility while maintaining enterprise-level security control through a dedicated authorization layer.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If traditional firewalls and VPN tunnels are used for access control, then network-level security is improved, but device-level access control capability deteriorates

Engineering Contradiction:
Improvenetwork securityVSAvoiddevice-level control
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments access control into multiple layers: network-level controls (firewalls, VPNs) and device-level controls (authorization service with distribution rules). The authorization service independently verifies device credentials and enforces distribution rules at the application layer, enabling fine-grained device-level control without compromising network-level security measures.

Inventive Principle:
Principle #1Segmentation

3Reliability

If device-level access control is implemented in cloud-based environments, then security is improved, but system complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authorization service acts as a centralized intermediary that manages the complexity of device-level access control. It handles credential authentication, distribution rule verification, and access decisions in one place, reducing the complexity burden on individual client devices and cloud infrastructure while maintaining comprehensive security control.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP2973188B1Secondary device as key for authorizing access to resources
Publication Date: 2021.11.24 AIRWATCH LLC
  • EP2973188B1 patent drawingFigure 1
  • EP2973188B1 patent drawingFigure 2
  • EP2973188B1 patent drawingFigure 3

AI summary

In a networked environment, a client side application executed on a client device may transmit a request to an authorization service for access to a resource. The authorization service may authenticate the user of client device and/or the client device based on user credentials and/or a device identifier. The authorization service may require that the client device comply with a distribution rule associated with the resource, where the distribution rule requires a specified secondary client device to be in communication with the client device as a prerequisite to accessing the resource. The client side application may determine that the client device complies with the distribution rule and may thereafter access the resources. In some cases, the secondary client device facilitates access to the resource, which may involve receiving from the secondary client device an authorization credential to be used for receiving authorization to access the resource.