Client Trust Levels for Secured Application Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Unified communications (UC) architectures face security risks due to the lack of authentication and trust verification in caller identities, allowing unauthorized access and potential information disclosure, as opposed to traditional PBX systems where physical access is required.

Innovation Solution

The proposed architecture creates and utilizes trust level information for endpoints during registration, which is verified by a communications infrastructure, allowing endpoints to selectively provide access to secured application features based on the trust levels, ensuring secure interactions and authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If UC architecture enables flexible communications with user identity authentication, then communication flexibility is improved, but security trust is worsened due to lack of verification

Engineering Contradiction:
Improvecommunication flexibilityVSAvoidsecurity trust
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system performs preliminary authentication and trust level assignment during the registration phase before actual communication occurs. The communications server assigns trust levels to endpoints based on authentication credentials, and this pre-established trust information is then used during call processing to control feature access, thereby enabling flexible communication while maintaining security trust through advance verification.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If physical access to phone/line is required for PBX, then security is improved, but communication flexibility is worsened

Engineering Contradiction:
ImprovesecurityVSAvoidcommunication flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent replaces the mechanical physical access requirement of traditional PBX systems with electronic authentication and trust level verification. Instead of requiring physical access to phones or lines, the system uses software-based authentication credentials and trust level assignments to control access, thereby maintaining security while enabling greater communication flexibility and mobility.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Ease of operation

If weak credentials are used for authentication, then ease of operation is improved, but security is worsened due to hacking risk

Engineering Contradiction:
Improveauthentication simplicityVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system changes the parameter of trust level assignment based on authentication method. Instead of treating all authentication methods equally, the system assigns different trust levels to different authentication scenarios (e.g., higher trust for stronger authentication methods). This allows the system to maintain ease of operation with various authentication methods while adjusting security measures based on the strength of the credentials used.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS9531695B2Access control to secured application features using client trust levels
Publication Date: 2016.12.27 MICROSOFT TECHNOLOGY LICENSING LLC
  • US9531695B2 patent drawing
  • US9531695B2 patent drawing
  • US9531695B2 patent drawing

AI summary

Architecture that facilitates the conveyance of a trust level when the caller makes a call, the trust level in dependence on the state of the caller system. The callee (call recipient) receives notification of the trust level and can use this information in the communication such as to request verification from the caller and/or initiate other modes of communication. A caller can authenticate the caller identity in different ways to a communication server. Based on that, the server can assign an appropriate server-verified trust level to the caller. Further, an unsecured phone controller can indicate a lower client-side defined trust level. The server verified and client-side trust levels are then sent to the callee, where the callee determines whether to allow caller access to one or more secured features based on the feature values and the trust level imposed by the callee to access those features.