Dynamic Authorization Ticket with Context Reinforcement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing dynamic authorization systems face challenges in reinforcing the reliability of context information, which is crucial for secure access management, especially in remote work and cloud computing environments where traditional access rules are inadequate.

Innovation Solution

A dynamic authorization system that includes a client terminal, an authorization server, and a context reinforcement device, where the client terminal acquires and sets context information in a ticket, and the authorization server uses reinforcement information to verify the scope, enhancing the reliability of context-based authorization.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If context information is used for authorization in remote work and cloud computing environments, then access flexibility across time and location is improved, but reliability of the authorization system deteriorates

Engineering Contradiction:
Improveaccess flexibilityVSAvoidauthorization reliability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces a ticket as an intermediary object that carries scope information between the client terminal and authorization server. This ticket mechanism enables flexible access by allowing authorization decisions to be made based on pre-defined scopes without requiring continuous connection to the authorization server, while maintaining reliability through structured verification of scope conditions including context information and reinforcement information.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements preliminary action by pre-defining scopes with authorization conditions before actual access requests. The authorization server evaluates context information and reinforcement information against these pre-defined scopes to make authorization decisions, enabling flexible access while maintaining security through advance preparation of authorization rules.

Inventive Principle:
Principle #10Preliminary action

2Productivity

If scope verification is performed using only context information from client terminal, then authorization speed is improved, but reliability of authorization decision deteriorates

Engineering Contradiction:
Improveauthorization speedVSAvoidauthorization decision reliability
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent introduces reinforcement information as an intermediary verification layer between context information and authorization decisions. The authorization server uses both context information (for speed) and reinforcement information (for reliability) to verify scopes, achieving a balance between quick authorization and reliable decision-making through this dual-verification approach.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements feedback by having the authorization server verify scopes using both context information provided by the client terminal and additional reinforcement information. This feedback mechanism ensures that authorization decisions are based on comprehensive verification while maintaining efficient processing through the structured scope evaluation approach.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS20240323176A1Dynamic authorization system and dynamic authorization method
Publication Date: 2024.09.26 MITSUBISHI ELECTRIC CORP
  • US20240323176A1 patent drawing
  • US20240323176A1 patent drawing
  • US20240323176A1 patent drawing

AI summary

A client terminal (200) acquires a ticket (110) including a scope indicating an authorization condition, collects a context to indicate a state of the client terminal, sets the context in the ticket, and transmits the ticket. The authorization server (400) receives the ticket, determines a condition element other than the context among one or more condition elements indicated in the authorization condition as reinforcement information (111), requests the reinforcement information determined to a context reinforcement device (500), receives the reinforcement information, and verifies the scope based on the context and the reinforcement information.