Dynamic Access Control via Data Broker Intermediary

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users face an undesirable experience due to the complexity of managing numerous passwords for various electronic systems, leading to forgotten passwords and increased susceptibility to hacking.

Innovation Solution

The system provides dynamic access to protected systems based on the amount and type of electronic data provided by client systems, using firewall rules and anonymizer circuitry to ensure secure and flexible access, while limiting information sharing to only what is requested.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional password-based authentication is used for each electronic system, then access security is maintained, but user complexity increases and security vulnerabilities arise from password management

Engineering Contradiction:
Improveaccess securityVSAvoidpassword management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a data broker as an intermediary component that mediates between client systems and protected systems. The data broker receives electronic data from clients, evaluates it against firewall rules, and dynamically grants access permissions without requiring users to manage passwords. This intermediary layer simplifies user interaction while maintaining security through automated data evaluation and access control.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system enables self-service authentication where client systems automatically provide electronic data (such as device identifiers, application information, or other metadata) to the data broker. The data broker then autonomously evaluates this data against stored firewall rules and dynamically determines access permissions, eliminating the need for manual password input and management by users.

Inventive Principle:
Principle #25Self-service

2Measurement precision

If comprehensive user data is collected for authentication, then access control precision improves, but data privacy risks increase

Engineering Contradiction:
Improveaccess control precisionVSAvoiddata privacy risks
Core Design Contradiction:
Measurement precisionVSObject-affected harmful factors

Solution Approach 1:

The patent implements local quality by evaluating specific attributes of electronic data locally at the data broker against corresponding firewall rules. Rather than collecting and centralizing all user data, the system evaluates only the necessary local attributes (such as device type, application identity, or data format) to determine access permissions. This localized evaluation approach maintains precise access control while minimizing data collection and privacy risks.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system performs preliminary action by pre-configuring firewall rules that define the exact data attributes and evaluation criteria needed for access control. These rules are established in advance, specifying which electronic data attributes should be evaluated and what thresholds or conditions must be met. This preliminary configuration enables precise access control decisions to be made based on pre-defined criteria without requiring real-time analysis of comprehensive user data.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12028323B1Layered authentication and priority access systems and methods
Publication Date: 2024.07.02 UNITED SERVICES AUTOMOBILE ASSOCIATION (USAA)
  • US12028323B1 patent drawing
  • US12028323B1 patent drawing
  • US12028323B1 patent drawing

AI summary

The present disclosure relates generally to systems and methods for providing dynamic access levels based upon permitted provision of client system data. In particular, proactive blocking of access to protected systems/services may be implemented when client system electronic data provision requirements of the protected systems/services are not met.