Dynamic Authorization Framework Token Generation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network administration systems face challenges in managing distributed access control across multiple elements in a corporate environment, where granting full administrative privileges is not always acceptable and adding administrative access for new elements is difficult without software modifications, and existing authorization standards like OAuth do not adequately address corporate access control needs.

Innovation Solution

An extended authorization framework is introduced that dynamically adds administrative access control by generating tokens, allowing for granular access management across network applications, using a plug-in to the existing authorization framework, which manages access control by determining the privileges of client applications accessing network applications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If full administrative privileges are granted to all elements in a distributed architecture, then access control is simplified, but security is compromised and granularity of control is lost

Engineering Contradiction:
Improveaccess control managementVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments administrative privileges into fine-grained permission levels. Instead of granting full administrative access to all elements, the system divides access control into specific permission types (read, write, execute, delete) that can be individually assigned to different elements based on their functional requirements. This segmentation resolves the contradiction by maintaining security through restricted access while simplifying operations through automated permission assignment.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements local quality by assigning different permission levels to different elements based on their specific roles and requirements. Each element receives customized access permissions tailored to its function rather than a uniform access level. This allows the system to maintain high security by restricting access where needed while enabling full functionality where required, thus resolving the contradiction between security and operational ease.

Inventive Principle:
Principle #3Local quality

2Adaptability or versatility

If the authorization framework is extended to support new administrative elements, then adaptability improves, but system complexity increases

Engineering Contradiction:
Improveadministrative access controlVSAvoidauthorization framework
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements universality by designing a standardized authorization framework that can accommodate multiple types of administrative elements (telephones, gateways, feature servers, etc.) through a common interface and permission model. New elements can be added without modifying the core framework structure, as they all interact through the same token-based authorization mechanism. This resolves the contradiction by enabling high adaptability while maintaining framework simplicity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent applies dynamics by making the authorization framework flexible and configurable. Permission assignments, token validity periods, and access policies can be dynamically adjusted without requiring system reconfiguration or software modifications. This dynamic capability allows the framework to adapt to new elements and changing requirements while maintaining a stable, simple core structure.

Inventive Principle:
Principle #15Dynamics

3Reliability

If granular access control is implemented, then security is improved, but ease of adding new administrative access is reduced

Engineering Contradiction:
Improveaccess control securityVSAvoidadding administrative access
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent implements self-service by enabling new administrative elements to automatically obtain appropriate permission tokens through the authorization framework without manual configuration. When a new element joins the system, it can autonomously request and receive the necessary access tokens based on its declared functional requirements. This resolves the contradiction by maintaining granular security control while simplifying the process of adding new elements through automated, self-configuring access assignment.

Inventive Principle:
Principle #25Self-service

4Ease of operation

If a standardized authorization framework is used, then ease of operation is improved, but flexibility for corporate-specific access control is reduced

Engineering Contradiction:
Improveaccess managementVSAvoidcorporate access control
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The patent applies dynamics by designing the standardized authorization framework to be configurable and adaptable to corporate-specific requirements. While maintaining a common standardized interface for ease of operation, the framework allows customization of permission types, access policies, and token validation rules to match organizational needs. This resolves the contradiction by enabling both standardized operation and corporate-specific flexibility through configurable parameters within the standard framework.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS10148522B2Extension of authorization framework
Publication Date: 2018.12.04 AVAYA INC
  • US10148522B2 patent drawing
  • US10148522B2 patent drawing
  • US10148522B2 patent drawing

AI summary

To provide better administrative access control for allowing access to network applications, an authorization framework is extended by dynamically adding administrative access control to the authorization framework. For example, the authorization framework can be extended by adding a plug-in to the authorization framework. The authorization framework manages the access control by generating tokens. For example, a token may be a digital certificate. The tokens define what access control an application, such as a client application has when accessing the network application. The tokens are based on the dynamically added administrative access control. When a request for a token is securely received, the authorization framework generates a token that identifies if the application (e.g., the client application) is allowed or not allowed to access the network application. The token is then used by the application to access the network application.