Centralized Subscription Manager for Distributed Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Distributed computing systems face challenges in managing user access and authentication across multiple computing resources, particularly in ensuring secure and fine-grained control over access to remote systems, as existing solutions lack centralized management and multi-level authentication mechanisms.

Innovation Solution

A system that centrally maintains user subscription information, including authentication and authorization details, and propagates relevant information to remote computing systems for user authentication and access control, utilizing multi-level authentication and password filtering to determine authorized access to specific resources.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If centralized management of user subscription information is implemented, then access control consistency across distributed systems is improved, but system complexity increases

Engineering Contradiction:
Improveaccess control consistencyVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a centralized subscription information manager as an intermediary component that stores and manages user authentication and authorization data. This manager acts as a mediator between users and multiple remote computing systems, providing consistent access control information across the distributed system without requiring complex peer-to-peer authentication mechanisms between systems.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The centralized subscription information manager serves multiple functions: storing user authentication information, maintaining system authorization information, providing relevant subscription information to remote systems, and enabling both authentication and authorization operations. This multi-functional approach reduces overall system complexity by consolidating these functions in a single component.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If multi-level authentication and password filtering are implemented, then security control is improved, but authentication process complexity increases

Engineering Contradiction:
Improvesecurity controlVSAvoidauthentication process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the authentication process into two distinct phases: authentication (verifying user identity through multilevel authentication and password checking) and authorization (determining access rights based on system authorization information). This segmentation allows each phase to be handled independently, reducing the perceived complexity of the overall authentication process while maintaining strong security controls.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary action by pre-storing system authorization information in the centralized subscription information manager before authentication occurs. This allows the authorization decisions to be made based on pre-configured rules rather than requiring complex real-time calculations during the authentication process, thereby simplifying the authentication flow while maintaining security.

Inventive Principle:
Principle #10Preliminary action

3Measurement precision

If centralized subscription information management is implemented, then access authorization accuracy is improved, but information management complexity increases

Engineering Contradiction:
Improveaccess authorization accuracyVSAvoidinformation management complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent implements local quality by providing different levels of subscription information to different remote computing systems based on their specific needs. The centralized manager stores comprehensive user subscription information but selectively provides only the relevant portions to each remote system, ensuring accurate authorization decisions while minimizing the information management burden on individual systems.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS9043878B2Method and system for multi-tiered distributed security authentication and filtering
Publication Date: 2015.05.26 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US9043878B2 patent drawing
  • US9043878B2 patent drawing
  • US9043878B2 patent drawing

AI summary

Multi-tiered distributed security authentication and filtering. One embodiment comprises managing user access to one or more computing resources, by centrally maintaining user subscription information comprising user authentication information and system authorization information, and providing relevant subscription information from the user subscription information to one or more remote computing systems. Managing user access further includes, in a remote computing system, authenticating a user login to the remote computing system based on user authentication information from said relevant subscription information, and upon user authentication, selectively authorizing user access to computing resources of the remote computing system based on system authorization information from said relevant subscription information.