Delegated Authorization Scope Management via Granular Obligation Policies
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current authorization systems, such as OAuth, lack granular control for resource owners over delegated access authorization scope and do not provide sufficient mechanisms for specifying and modifying obligation policies, leading to potential over-permissive access grants.
Innovation Solution
A method and system that allow resource owners to define and manage delegated authorization grants through a user interface, enabling granular control over access scopes and obligation policies, ensuring that access is limited and conditioned by the defined scope, with the ability to modify policies dynamically.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If OAuth authorization is delegated to third party applications, then access to resource owner's data is enabled, but granular control over authorization scope is lost
Solution Approach 1:
The patent segments authorization scope into discrete, selectable permissions that resource owners can individually grant or deny. Instead of all-or-nothing authorization, the system divides access rights into granular units that can be independently controlled, allowing precise scope management without overwhelming complexity.
Solution Approach 2:
The patent implements dynamic authorization scope adjustment, allowing resource owners to modify granted permissions at any time. The authorization scope is not fixed but can be dynamically expanded or contracted based on changing needs, providing adaptability while maintaining simple user-facing controls.
2Ease of operation
If broad authorization scope is granted to third party applications, then access functionality is improved, but security risk increases due to potential over-permissive access
Solution Approach 1:
The patent applies local quality by allowing different authorization levels for different data types or operations within the same resource. Instead of uniform authorization scope, specific portions of data or specific operations can have tailored access permissions, enabling fine-grained security control while maintaining operational simplicity.
3Reliability
If authorization scope is tightly controlled, then security is improved, but ease of use deteriorates due to complex consent management
Solution Approach 1:
The patent implements self-service authorization management where resource owners can independently view, modify, and revoke their own authorization grants without administrator intervention. This empowers users to manage their own security preferences simply, maintaining high security through user control while eliminating complex administrative overhead.
Data Source
AI summary
A method sends a request for a delegated authorization grant data set, receives a delegated authorization grant data set that defines the delegated authorization grant scope, with respect to a resource. The delegated authorization grant data set includes a scope variable value having been selected by a delegator entity through a delegation grant scope user interface on the delegator device. The scope controls access to the resource in a manner limited by the scope of the delegated authorization grant defined by the delegated authorization grant data set.


