Conditional Authorization for Isolated Data Collections

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing authorization systems for electronic information are often complex and resource-intensive, requiring extensive architectures and services for enrollment, token generation, and life-cycle management, making them less desirable for resource-efficient scenarios.

Innovation Solution

A system and method for conditionally authorizing access to isolated collections of data, where requests are evaluated against defined conditions, allowing or denying access based on whether these conditions are met, using resource identifiers and relationships managed through an application or service that interrogates resource providers for authorization information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional authorization systems are implemented, then access control and security are improved, but system complexity and resource consumption increase

Engineering Contradiction:
Improveaccess control securityVSAvoidauthorization system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the authorization system into isolated collections of resources, where each collection can be independently authorized. This segmentation allows the system to manage complex authorization requirements by breaking them into smaller, manageable units rather than implementing a monolithic complex system.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary application that acts as a mediator between resource providers and resource consumers. This intermediary handles the authorization logic and condition evaluation, simplifying the overall system architecture while maintaining security through a centralized authorization point.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If comprehensive authorization services are deployed, then access control capability is improved, but resource overhead increases

Engineering Contradiction:
Improveaccess control capabilityVSAvoidcomputational resource overhead
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent implements local quality by allowing different authorization conditions to be applied to different isolated collections based on their specific security requirements. This enables the system to apply comprehensive authorization only where needed rather than uniformly across all resources, reducing overall resource overhead.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent applies partial action by implementing authorization only for specific isolated collections that require it, rather than deploying comprehensive authorization services across the entire system. This selective approach reduces resource overhead while maintaining necessary security capabilities.

Inventive Principle:
Principle #16Partial or excessive action

3Measurement precision

If fine-grained access control is implemented, then security precision is improved, but system complexity increases

Engineering Contradiction:
Improveaccess control precisionVSAvoidauthorization system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments resources into isolated collections with specific access conditions, enabling fine-grained control over each collection. This segmentation approach achieves precision without requiring a single complex centralized system, as each collection can be independently configured and managed.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentEP3535947B1Conditional authorization for isolated collections
Publication Date: 2021.03.31 MICROSOFT TECHNOLOGY LICENSING LLC
  • EP3535947B1 patent drawingFigure 1
  • EP3535947B1 patent drawingFigure 2
  • EP3535947B1 patent drawingFigure 3A

AI summary

Examples of the present disclosure describe systems and methods of conditionally authorization access to isolated collections of data. In aspects, a request to access an isolated collection of resource identifiers and relationships may be received by an application. A set of conditions may control access to the isolated collection. Upon receiving the request, the application may attempt to determine whether the set of conditions has been satisfied. If the set of conditions is determined to be satisfied, the application may provide the requestor with access to the isolated collection. If the set of conditions is determined to be unsatisfied, the application may prohibit the requestor from accessing the isolated collection.