Delegated Authorization Scope Management via Granular Obligation Policies

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current authorization systems, such as OAuth, lack granular control for resource owners over delegated access authorization scope and do not provide sufficient mechanisms for specifying and modifying obligation policies, leading to potential over-permissive access grants.

Innovation Solution

A method and system that allow resource owners to define and manage delegated authorization grants through a user interface, enabling granular control over access scopes and obligation policies, ensuring that access is limited and conditioned by the defined scope, with the ability to modify policies dynamically.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If OAuth authorization is delegated to third party applications, then access to resource owner's data is enabled, but granular control over authorization scope is lost

Engineering Contradiction:
Improveauthorization scope controlVSAvoidauthorization management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments authorization scope into discrete, selectable permissions that resource owners can individually grant or deny. Instead of all-or-nothing authorization, the system divides access rights into granular units that can be independently controlled, allowing precise scope management without overwhelming complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements dynamic authorization scope adjustment, allowing resource owners to modify granted permissions at any time. The authorization scope is not fixed but can be dynamically expanded or contracted based on changing needs, providing adaptability while maintaining simple user-facing controls.

Inventive Principle:
Principle #15Dynamics

2Ease of operation

If broad authorization scope is granted to third party applications, then access functionality is improved, but security risk increases due to potential over-permissive access

Engineering Contradiction:
Improveaccess grant simplicityVSAvoidaccess authorization security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent applies local quality by allowing different authorization levels for different data types or operations within the same resource. Instead of uniform authorization scope, specific portions of data or specific operations can have tailored access permissions, enabling fine-grained security control while maintaining operational simplicity.

Inventive Principle:
Principle #3Local quality

3Reliability

If authorization scope is tightly controlled, then security is improved, but ease of use deteriorates due to complex consent management

Engineering Contradiction:
Improveaccess authorization securityVSAvoidconsent management ease
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements self-service authorization management where resource owners can independently view, modify, and revoke their own authorization grants without administrator intervention. This empowers users to manage their own security preferences simply, maintaining high security through user control while eliminating complex administrative overhead.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS9906558B2User managed access scope specific obligation policy for authorization
Publication Date: 2018.02.27 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US9906558B2 patent drawing
  • US9906558B2 patent drawing
  • US9906558B2 patent drawing

AI summary

A method sends a request for a delegated authorization grant data set, receives a delegated authorization grant data set that defines the delegated authorization grant scope, with respect to a resource. The delegated authorization grant data set includes a scope variable value having been selected by a delegator entity through a delegation grant scope user interface on the delegator device. The scope controls access to the resource in a manner limited by the scope of the delegated authorization grant defined by the delegated authorization grant data set.