Dynamic Permission Activation for E-Learning Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing eLearning systems face security risks due to compromised client computers or user accounts, allowing unauthorized access and malicious activities, despite traditional authentication methods like usernames and passwords, which can be vulnerable to hacking and do not adequately prevent background malicious actions.

Innovation Solution

Implementing a security verification system that activates specific permission sets based on command-specific requirements and operational contexts, using customizable security verification processes to ensure secure execution of commands, rather than relying solely on account identifiers, thereby enhancing security without compromising convenience.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If traditional authentication methods (username and password) are used, then user access is facilitated, but security vulnerabilities increase allowing unauthorized access and malicious activities

Engineering Contradiction:
Improveuser access facilitationVSAvoidsecurity vulnerability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments authentication into multiple independent stages: initial authentication via username/password, then subsequent command-level authentication requiring additional credentials. This segmentation ensures that even if initial authentication is compromised, further unauthorized actions are blocked by additional security layers.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary authentication actions before executing commands. Additional authentication credentials are required in advance of command execution, preventing unauthorized actions even if initial credentials are compromised. This preliminary verification step blocks malicious activities before they can occur.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If additional security verification processes are implemented, then security against compromised accounts is improved, but system complexity increases

Engineering Contradiction:
Improvesecurity verificationVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system dynamically adjusts authentication requirements based on the command being executed. Different commands may require different additional credentials, allowing the security mechanism to adapt to the specific context rather than applying a static complex authentication process to all operations.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent introduces an intermediary authentication layer that sits between the user and the system resources. This intermediary verifies additional credentials and acts as a mediator, approving or blocking commands based on authentication status without requiring complete system redesign.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If multiple user accounts with different permissions are created, then security control is improved, but account management complexity increases

Engineering Contradiction:
Improvepermission controlVSAvoidaccount management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Instead of requiring complete separate accounts for every permission level, the system uses partial authentication actions. A single account can execute some commands with basic authentication and requires additional verification only for specific privileged commands, reducing the need for multiple accounts while maintaining security control.

Inventive Principle:
Principle #16Partial or excessive action

4Reliability

If command-specific permission sets are activated, then unauthorized command execution is prevented, but processing time increases

Engineering Contradiction:
Improvecommand execution securityVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system implements periodic authentication where additional credentials are required at specific intervals or for specific command types rather than continuously. This periodic verification maintains security for critical operations while allowing faster processing for routine commands that don't require additional authentication.

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS9396327B2Systems and methods for security verification in electronic learning systems and other systems
Publication Date: 2016.07.19 DESIRE2LEARN
  • US9396327B2 patent drawing
  • US9396327B2 patent drawing
  • US9396327B2 patent drawing

AI summary

The embodiments described herein relate to security verification systems and methods. In some aspects, there is provided a security verification server comprising a server processor. The server processor is adapted to provide at least one account identifier, receive at least one command for execution, determine whether to activate one or more available additional permission sets to execute the received command, and if it is determined that one or more additional permission sets should be activated to execute the received command, activate those permission sets by executing the security verification processes associated therewith.