Cross-Organization Trusted Relationship Establishment via Challenge-Response

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Organizational communication systems often restrict cross-organizational communication, leading to security and privacy issues when users attempt to bypass these limitations, preventing seamless communication between users from different organizations despite mutual trust.

Innovation Solution

A system where servers automatically establish a trusted relationship between users based on their communication history by sending challenges and responses, ensuring secure and controlled access to communication resources without revealing sensitive information, with customizable trust levels and encryption options.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If organizational communication systems restrict cross-organizational communication to maintain security and privacy, then data security and organizational policy compliance are improved, but communication capability and user flexibility deteriorate

Engineering Contradiction:
Improvedata securityVSAvoidcommunication capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces a challenge-response mechanism as an intermediary verification layer between organizations. When a user from one organization attempts to communicate with a user from another organization, the system automatically generates a challenge based on communication history and verifies it through a response. This intermediary process enables secure cross-organizational communication without requiring full organizational trust, thus resolving the contradiction between security restrictions and communication capability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If users install instant communicator programs or add personal email accounts to bypass organizational limitations, then communication flexibility is improved, but data security and network security deteriorate

Engineering Contradiction:
Improvecommunication flexibilityVSAvoiddata security risks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system implements automated challenge-response verification that occurs without user awareness or manual intervention. When communication is attempted between users from different organizations, the servers automatically generate challenges based on communication history, exchange responses, and establish trust relationships. This self-service mechanism provides secure communication flexibility without requiring users to install external applications or bypass organizational policies manually.

Inventive Principle:
Principle #25Self-service

3Productivity

If servers automatically establish trusted relationships based on communication history, then communication efficiency is improved, but system complexity and privacy concerns worsen

Engineering Contradiction:
Improvecommunication efficiencyVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent extracts only the necessary elements from communication history to form challenges, rather than analyzing or storing entire communication records. The system selects specific communication events, extracts relevant identifiers and timestamps, and uses these extracted elements to generate verification challenges. This extraction approach enables automated trust establishment while minimizing privacy concerns and reducing the complexity of processing and storing comprehensive communication histories.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS9324057B2System and method for establishing a relationship based on a prior association
Publication Date: 2016.04.26 AVAYA INC
  • US9324057B2 patent drawing
  • US9324057B2 patent drawing
  • US9324057B2 patent drawing

AI summary

Disclosed herein are systems, methods, and non-transitory computer-readable storage media for automatically establishing trusted relationships between users across organizational boundaries. A user makes a request to his system to create a trusted relationship with an individual of another organization. The system then analyzes the previous communication history between the user and the other individual, and, based on that analysis, sends a query to the other individual's system. The system then receives a response from the other individual's system, and if the response matches an expected response the system forms a trusted relationship between the user and the other individual.