Dynamic URI File Access Control with Identity Provider Validation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing file management systems face challenges in efficiently generating, storing, and retaining files while ensuring secure access and compliance with regulatory requirements, particularly in managing large volumes of formal files suitable for official communication.
Innovation Solution
A method for managing file generation, storage, and deletion that involves using non-volatile memory to store files, generating URIs associated with files, validating user identities through a server and identity provider, and granting access based on identity validation responses.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If manual file generation and management is used, then file creation can be performed, but efficiency is low and error rate increases
Solution Approach 1:
The system enables automatic file generation, storage, and management without requiring manual intervention. The server automatically generates files from templates, stores them in non-volatile memory, creates URIs, manages access control, and handles retention policies, allowing the system to serve itself and eliminating the need for manual file management operations.
Solution Approach 2:
The patent replaces manual mechanical file management operations with an automated server-based system. Instead of manually creating and managing files, the system uses server processes to automatically generate files from templates, store them, manage access control, and enforce retention policies, substituting human operations with automated computational processes.
2Reliability
If traditional server file storage is used, then files can be stored and accessed, but security and access control are insufficient
Solution Approach 1:
The patent introduces an identity provider as an intermediary between the server and the user authentication process. The identity provider validates user identities and issues authentication information to the server, adding a layer of security without requiring the server to directly manage complex authentication logic. This intermediary handles the complexity of identity validation while maintaining secure access control.
Solution Approach 2:
The access control system is segmented into separate functional components: the server handles file storage and URI generation, while the identity provider handles authentication and authorization. This segmentation allows each component to focus on specific security functions, improving overall security without requiring a single complex system to handle all security requirements.
3Reliability
If comprehensive access validation is implemented, then security is enhanced, but system complexity increases
Solution Approach 1:
The identity provider serves as an intermediary that handles complex identity validation tasks. Instead of the server directly implementing complex authentication logic, the identity provider performs these validation functions and returns authentication information to the server, reducing the complexity burden on the server while maintaining high validation accuracy.
Solution Approach 2:
The identity provider is designed as a universal authentication service that can validate various types of user identities and provide authentication information to multiple servers. This multi-functional approach consolidates authentication complexity into a single reusable service, improving validation accuracy without requiring each individual server to implement complex authentication logic.
Data Source
AI summary
The present disclosure relates to methods for administering access to generated files. The method involves storing a file on a server. The server receives a request from a first client device to generate a uniform resource identifier (URI) associated with the file, an identity, and a dynamic expire time. The server generates the URI, which links to a resource comprising the file, and transmits it to a second client device. The server then receives a request from the second client device using the URI to request the resource. The server validates the identity by checking it against a database of authorized identities. Additionally, the server validates the identity through an identity provider, which prompts the user to login to the identity on an identity hosting platform. Based on the response from the server and the identity provider, access to the resource is granted or denied. Based on that access and retention parameters, viewing is allowed, or may be removed if credentials such as viewing time or count is exceeded or biometric scan fail.


