Dynamic Access Gateway for Restricted Functionality

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems lack effective methods to provide users with access to restricted functionality within organizations, such as internal business systems, while maintaining security and integration with publicly available information.

Innovation Solution

A restricted functionality access provider system that executes on client computing systems, interacting with presentation programs to dynamically modify user interfaces and provide access to restricted functionality based on user authorization, using APIs and extensions like browser extensions to offer additional user-selectable controls and information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If users are granted access to internal organizational functionality, then operational efficiency and user interaction are enhanced, but security risks increase

Engineering Contradiction:
Improveoperational efficiencyVSAvoidsecurity risks
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent implements a gateway component that acts as an intermediary between users and internal organizational functionality. This gateway evaluates user credentials, device states, and contextual information to dynamically determine access permissions. The gateway mediates access requests by translating public website interactions into authenticated access to internal systems, thereby enabling operational efficiency while maintaining security through centralized authorization control.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The access control system dynamically adjusts permissions based on real-time evaluation of user credentials, device security states, and contextual factors. The system transitions from static access control to dynamic authorization, where permissions are granted, modified, or revoked based on current conditions. This dynamic approach allows the system to enhance operational efficiency for authorized users while maintaining security by adapting access levels to current risk assessments.

Inventive Principle:
Principle #15Dynamics

2Ease of operation

If restricted functionality is made accessible through public interfaces, then ease of operation improves, but system security deteriorates

Engineering Contradiction:
ImproveaccessibilityVSAvoidsystem security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The gateway serves as an intermediary layer between public website interfaces and internal organizational systems. It enables users to access restricted functionality through familiar public interfaces while secretly evaluating and enforcing security policies. The gateway translates simple user actions into authenticated access requests, maintaining ease of operation while preserving system security through behind-the-scenes authorization checks.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system segments access control into multiple independent evaluation components within the gateway, assessing different security factors (user credentials, device state, contextual information) separately before making an authorization decision. This segmentation allows the system to maintain simple public interfaces while implementing comprehensive security checks, improving ease of operation without compromising reliability.

Inventive Principle:
Principle #1Segmentation

3Adaptability or versatility

If integration between public and internal systems is deepened, then functionality versatility increases, but system complexity increases

Engineering Contradiction:
Improvefunctionality integrationVSAvoidsystem architecture
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The gateway acts as a unified intermediary that handles all integration between public and internal systems through a single architectural component. Rather than creating multiple integration points throughout the system, the gateway centralizes access control functionality, evaluating security policies and managing authentication in one location. This approach enables deep functionality integration while minimizing system complexity by avoiding distributed security implementations.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If authentication requirements are strengthened, then security reliability improves, but ease of operation deteriorates

Engineering Contradiction:
Improvesecurity authenticationVSAvoiduser accessibility
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The authentication system implements self-service mechanisms where users automatically provide credentials and the gateway automatically evaluates security policies without requiring manual intervention. The system autonomously assesses user credentials, device states, and contextual information, granting access decisions without user effort. This self-service approach strengthens security reliability through comprehensive authentication while maintaining ease of operation by eliminating manual security steps for users.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10049226B1Facilitating access to restricted functionality
Publication Date: 2018.08.14 AMAZON TECH INC
  • US10049226B1 patent drawing
  • US10049226B1 patent drawing
  • US10049226B1 patent drawing

AI summary

Techniques are described for facilitating access of computing system users to restricted functionality, such as internal functionality of a business or other organization (e.g., internal systems and/or confidential information available to some or all business employees or other organization members). The restricted functionality access may in some situations be provided in conjunction with publicly available information from the organization, such as to use that publicly available information as part of a user interface that allows an authorized subset of users to access the restricted functionality. In some situations, the restricted functionality access may be facilitated by an access provider system that executes on a client computing system of an authorized user, such as a program operating in conjunction with another presentation program that presents publicly available information (e.g., as an extension program for the presentation program), and that modifies the interactions available to the user when using the presentation program.