Authorization Management Using Signed Data Packets
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current authorization systems for computing devices are insecure due to the lack of secure elements in most mobile devices, requiring online verification which is unreliable and complex, and existing solutions like hardware tokens are inconvenient.
Innovation Solution
A method using a token infrastructure with a token computing system, kiosk computing system, and user computing system to generate and manage electronically signed authorization tokens without requiring a secure element, allowing for secure authentication and authorization without online verification.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If online verification is used for authorization, then security can be maintained, but reliability deteriorates due to dependency on stable data connection
Solution Approach 1:
The authorization mechanism is divided into multiple independent components: token computing system, kiosk computing system, and user computing system. Each component generates and processes authorization tokens independently, eliminating the need for continuous online verification while maintaining security through distributed authentication.
Solution Approach 2:
The patent uses electronically signed authorization tokens that can be copied and stored on user computing devices. These tokens contain all necessary authorization information and can be presented to kiosk computing systems without requiring real-time connection to the token computing system, enabling offline authorization verification.
2Reliability
If hardware tokens are used for secure authentication, then security is improved, but ease of operation deteriorates due to need to carry additional devices
Solution Approach 1:
The patent combines the token computing system, kiosk computing system, and user computing system into an integrated networked environment where authorization tokens are generated and managed software-based. This eliminates the need for separate hardware tokens while maintaining security through cryptographic authentication across multiple computing systems.
Solution Approach 2:
The authorization token system serves multiple functions: user identification, authentication, authorization granting, and token validation. The same electronically signed data packets perform all these functions without requiring separate hardware devices, making the system more versatile and easier to use.
3Reliability
If secure elements are built into mobile devices, then authentication security is improved, but device complexity increases and access becomes restricted
Solution Approach 1:
The patent introduces an intermediary authorization token system that mediates between the token computing system and user computing systems. These tokens act as portable credentials that can be generated and stored on various computing devices without requiring secure elements, enabling flexible access for outside developers while maintaining security through cryptographic signing.
Solution Approach 2:
The system dynamically generates and manages authorization tokens that can be created, validated, and revoked as needed. The tokens include time-to-live parameters and can be adapted to different authorization scenarios, providing flexibility without requiring permanent secure hardware installations on each device.
Data Source
Figure 1~2
AI summary
The invention relates to a method for managing authorizations on an arrangement having multiple computer systems, wherein a first computer system (105) produces a first data packet, which is used to identify a user, and produces a second data packet, which indicates an authorization of the user, the second data packet being produced on the basis of the first data packet. The two data packets are provided with a signature and transmitted to a user computer system (101). A function on an application system (100), which is different from the user computer system (101), is enabled after the following steps are performed: receipt of the first and second data packets from the user computer system (101), a check to determine whether the user computer system (101) is authorized to use the first data packet, a check to determine whether the first and second data packets are provided with a valid signature, a check to determine whether the first and second data packets are associated, and a check to determine whether a piece of authorization information contained in the second data packet authorizes enabling of the function on the application system (100).