Client Device Blockchain Authorization for Broker Offline Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In broker-based systems, when the cloud-based broker device is offline, there is a challenge in storing authorizations for client devices to connect to server resources without additional storage and ensuring trust between client devices and server resources in the absence of a centralized source of trust.

Innovation Solution

Implementing blockchain technology to store and validate pre-established client-server authorizations, allowing decentralized storage and validation of connection leases, enabling client devices to connect to broker resources even when the broker server is unavailable by using blockchain information for connection establishment and validation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the broker device is in the cloud and offline, then client devices cannot connect to server resources through the broker, but introducing additional storage components increases system complexity and cost

Engineering Contradiction:
Improveconnection availabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system performs preliminary actions by storing authorization data and blockchain information in the client device before the broker device goes offline. This pre-stored information enables the client device to autonomously establish connections to server resources without requiring the broker device to be online, thereby maintaining connection availability while avoiding the need for additional storage components.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system creates a copy of the authorization data and blockchain information from the broker device and stores it locally in the client device. This copying mechanism allows the client device to access necessary authorization information independently when the broker device is offline, eliminating the need for additional centralized storage components while maintaining system reliability.

Inventive Principle:
Principle #26Copying

2Reliability

If the broker device is offline, then centralized trust validation cannot be performed, but maintaining trust between client devices and server resources requires additional components

Engineering Contradiction:
Improvetrust validationVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system implements self-service by enabling the client device to autonomously validate authorizations using pre-stored blockchain information when the broker device is offline. The client device independently verifies the blockchain data and establishes connections without requiring centralized trust validation, thereby maintaining trust reliability while avoiding additional system components.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary trust validation by storing verified blockchain information and authorization data in the client device before the broker device goes offline. This pre-validated information enables the client device to autonomously perform trust validation without requiring the broker device to be online, maintaining reliability while avoiding additional components.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If additional storage components are introduced to store authorizations, then authorization storage is possible when broker is offline, but system cost and complexity increase

Engineering Contradiction:
Improveauthorization availabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system applies multi-functionality by utilizing the existing client device's local storage capabilities to store authorization data and blockchain information. Instead of introducing dedicated storage components, the client device's existing storage is used for multiple purposes including application data, blockchain information, and authorization credentials, thereby maintaining authorization availability while avoiding additional system complexity and cost.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system merges the storage of authorization data, blockchain information, and connection credentials into the client device's existing storage infrastructure. This consolidation eliminates the need for separate dedicated storage components while ensuring authorization information is available when the broker device is offline, maintaining reliability without increasing system complexity.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS10778603B2Systems and methods for controlling access to broker resources
Publication Date: 2020.09.15 CITRIX SYSTEMS INC
  • US10778603B2 patent drawing
  • US10778603B2 patent drawing
  • US10778603B2 patent drawing

AI summary

Systems and methods for controlling access to broker resources. The methods comprising: receiving, by a client device from a broker server, a list of broker resources that a user is permitted to access and blockchain information for connecting with each broker resource of the list; detecting when the broker server become unavailable; and using the blockchain information to control connection establishment between the client device and at least a first resource of the broker resources in the list while the broker server is unavailable.