Automated Social Network Contact Authorization via Security Policies

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing social network systems require users to manually approve contact requests, which can be time-consuming and inefficient, especially in hierarchical or organizational settings where automatic connections would simplify collaboration and resource deployment.

Innovation Solution

A method and system that allow users to add contacts without approval, based on predefined security policies and social hierarchies, enabling automatic connections within organizations and between organizations during emergencies or projects, using a social networking service that accesses these policies to determine authorization for contact additions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual approval is required for contact requests, then user security and control are improved, but time consumption and operational efficiency deteriorate

Engineering Contradiction:
Improveuser security and controlVSAvoidtime consumption
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system changes the authorization parameter from binary (approve/deny) to multi-level based on security policies. Users can configure different authorization levels for different user groups, allowing automatic connection for certain categories while maintaining manual approval for others, thus resolving the contradiction between security control and time efficiency

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The system enables self-service through pre-configured security policies that automatically determine connection authorization without requiring manual user intervention. The policies themselves serve the system by automatically evaluating connection requests and making authorization decisions, eliminating time-consuming manual approvals while maintaining security standards

Inventive Principle:
Principle #25Self-service

2Ease of operation

If manual approval is required for contact requests, then user control over contacts is improved, but administrative burden and complexity increase

Engineering Contradiction:
Improveuser controlVSAvoidadministrative burden
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

Users perform preliminary action by configuring their security policies in advance, specifying which user groups or categories require manual approval and which allow automatic connections. This preliminary configuration reduces the administrative burden during actual connection operations while maintaining user control over the authorization logic

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

Security policies act as an intermediary between user control requirements and connection requests. The policies mediate by automatically evaluating requests against predefined criteria, reducing the need for direct user intervention in each connection request while preserving user control through policy configuration

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If automatic connections are enabled, then collaboration efficiency is improved, but security control and user authorization may be compromised

Engineering Contradiction:
Improvecollaboration efficiencyVSAvoidsecurity control
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system changes the security control parameter from uniform manual approval to differentiated authorization levels based on security policies. Automatic connections are enabled for users meeting policy criteria (e.g., same organization, verified profiles) while maintaining manual approval for others, thus achieving both collaboration efficiency and security control

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

Security policies perform self-service by automatically evaluating connection requests against predefined security criteria. The policies independently determine whether automatic connection is appropriate, enabling efficient automatic connections for authorized users while maintaining security control without requiring manual review for each request

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11516164B2Establishing social network connections
Publication Date: 2022.11.29 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US11516164B2 patent drawing
  • US11516164B2 patent drawing
  • US11516164B2 patent drawing

AI summary

A request initiated by a first user in a social network to add at least a second user of the social network as a contact of the first user in the social network can be received. A security policy for the second user can be accessed and, based on the security policy, whether the first user is authorized to add the second user as the contact of the first user in the social network without the second user being prompted to approve the request can be determined. Responsive to determining that the first user is authorized to add the second user as the contact of the first user in the social network without prompting the second user to approve the request, the second user can be added as the contact of the first user in the social network without prompting the second user to approve the request.