Dynamic Credential-Based Addressing for Resource Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Managing computing resources across a growing number of devices and users in organizations is inefficient, particularly in ensuring security and providing applications, as existing methods require significant administrative time and effort, and allowing users to bring their own devices complicates security and resource distribution.

Innovation Solution

A method that dynamically configures a virtual address space by identifying access information for configuration resources, generating mappings of virtual addresses to both local and network resources using Uniform Resource Identifiers (URIs), allowing seamless access to both local and external resources as if they were stored locally, thereby simplifying resource management and security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If administrators manually manage and configure hardware and software for each individual user device, then security and resource distribution can be controlled, but the administrative time and effort increase significantly as the number of devices and users grow

Engineering Contradiction:
Improvesecurity controlVSAvoidadministrative time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system enables self-service through automatic device identification and credential-based resource allocation. When a user logs in with credentials, the system automatically identifies their device, determines appropriate computing resources based on stored credential information, and configures the virtual address space without administrator intervention. This eliminates manual configuration time while maintaining security through credential verification.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary action by pre-storing credential information and device identification data in advance. Before resource allocation is needed, the system already has user credentials, device identifiers, and resource mapping rules prepared. When a user accesses the system, this pre-prepared information enables immediate automatic configuration without requiring administrators to manually gather and process this information at the time of resource allocation.

Inventive Principle:
Principle #10Preliminary action

2Adaptability or versatility

If users are allowed to bring their own devices (smartphones, tablets, computers), then users can use devices they are comfortable with, but it becomes difficult to ensure security and distribute resources uniformly

Engineering Contradiction:
Improvedevice choiceVSAvoidsecurity assurance
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system achieves universality by creating a credential-based resource allocation mechanism that works across multiple device types (smartphones, tablets, computers). Instead of requiring device-specific configuration, the system uses universal credential verification to identify users and automatically determine appropriate resources. This allows users to bring any device while maintaining uniform security policies and resource distribution rules across all device types.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system introduces credentials as an intermediary between the user's diverse devices and the resource management system. Rather than directly managing each device type, the system uses credential information as a mediator to verify user identity, determine resource requirements, and configure access. This intermediary approach enables secure resource allocation regardless of the specific device being used, as long as the user can provide valid credentials.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If computing resources are dynamically allocated based on user credentials, then resource management efficiency improves and administrative burden reduces, but the system complexity increases

Engineering Contradiction:
Improveresource management efficiencyVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The system applies segmentation by dividing the complex resource allocation process into distinct functional modules: credential verification, device identification, resource determination, and virtual address space configuration. Each module handles a specific aspect of the allocation process independently. This segmentation improves productivity by enabling automatic parallel processing of multiple user requests while managing complexity through modular design, where each segment can be developed and maintained separately.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system uses copying by creating virtual representations of physical computing resources through virtual address spaces. Instead of directly managing physical hardware allocation, the system creates virtual copies or abstractions of resources that can be dynamically assigned to users based on credentials. This copying approach improves productivity by enabling flexible resource allocation without physical reconfiguration, while managing complexity by working with software-based virtual representations rather than direct hardware control.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS10778636B2Dynamic credential based addressing
Publication Date: 2020.09.15 COLORTOKENS INC
  • US10778636B2 patent drawing
  • US10778636B2 patent drawing
  • US10778636B2 patent drawing

AI summary

Techniques to facilitate enhanced addressing of local and network resources from a computing system are provided herein. In one implementation, a method of mapping a virtual address space for an application on a computing system includes in response to initiating the application, identifying access information for at least one configuration resource. The method further includes transferring a request to the at least one configuration resource for a virtual addressing configuration, and receiving the virtual addressing configuration from the at least one configuration resource. The method further provides, based on the virtual addressing configuration, generating a mapping of virtual addresses for the application to local addresses for local resources and network addresses and network addresses for network resources.