Dynamic Trust Realm Derivation for Secure Administrative Domain Interactions

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security federation models fail to dynamically and securely facilitate interactions between administrative domains during collaborative processes, lacking efficient mechanisms for trust realm derivation and secure communication establishment.

Innovation Solution

The proposed solution involves modeling interactions using Web Services Choreography Description Language (WS-CDL) to specify role information and interactions between administrative domains, dynamically resolving appropriate domains based on role information, and automatically deriving trust realms for secure communication through the issuance of security tokens and format conversion.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If traditional pre-defined interaction models are used, then entities can interact in a preset sequence, but the system lacks adaptability when collaboration needs arise dynamically

Engineering Contradiction:
ImproveadaptabilityVSAvoidcomplexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements dynamic service composition where the interaction model transitions from static pre-defined sequences to runtime-determined collaborations. The system dynamically resolves appropriate administrative domains based on role information and automatically derives trust realms when collaboration needs arise, allowing the interaction structure to adapt flexibly to changing requirements while maintaining security through automated trust establishment

Inventive Principle:
Principle #15Dynamics

2Adaptability or versatility

If dynamic resolution of administrative domains is implemented, then the system gains flexibility in selecting appropriate enterprises, but trust establishment becomes more complex

Engineering Contradiction:
ImproveflexibilityVSAvoidtrust establishment complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system implements automated self-service mechanisms where the trust realm derivation occurs automatically when collaboration needs arise. The system autonomously resolves appropriate administrative domains based on role information and establishes trust relationships without manual intervention, reducing the perceived complexity for users while maintaining robust security through automated cryptographic operations and trust negotiation

Inventive Principle:
Principle #25Self-service

3Speed

If secure interactions are established dynamically, then the system can respond to collaboration needs in real-time, but the time required for trust realm derivation increases

Engineering Contradiction:
Improveresponse speedVSAvoidtrust derivation time
Core Design Contradiction:
SpeedVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-establishing the framework for trust realm derivation and maintaining role information repositories in advance. When collaboration needs arise, the system leverages these pre-prepared structures to rapidly resolve appropriate administrative domains and derive trust realms, significantly reducing the time required compared to establishing security relationships from scratch while maintaining real-time responsiveness

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8104069B2Establishment of security federations
Publication Date: 2012.01.24 SAP SE
  • US8104069B2 patent drawing
  • US8104069B2 patent drawing
  • US8104069B2 patent drawing

AI summary

Secure interactions between administrative domains are modeled. The modeled process specifies role information for each of the administrative domains and interaction between the administrative domains. Role information associated with candidate administrative domains is received, and appropriate administrative domains from the candidate administrative domains are dynamically resolved based on the modeled process and the received role information. Trust realms between the dynamically resolved appropriate administrative domains are automatically derived based on the role information and the interactions from the modeled process. The secure interaction between the dynamically resolved appropriate administrative domains is effected through the automatically derived trust realms.