Dynamic URI File Access Control with Identity Provider Validation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing file management systems face challenges in efficiently generating, storing, and retaining files while ensuring secure access and compliance with regulatory requirements, particularly in managing large volumes of formal files suitable for official communication.

Innovation Solution

A method for managing file generation, storage, and deletion that involves using non-volatile memory to store files, generating URIs associated with files, validating user identities through a server and identity provider, and granting access based on identity validation responses.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If manual file generation and management is used, then file creation can be performed, but efficiency is low and error rate increases

Engineering Contradiction:
Improvefile generation efficiencyVSAvoidtime consumed for manual file management
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The system enables automatic file generation, storage, and management without requiring manual intervention. The server automatically generates files from templates, stores them in non-volatile memory, creates URIs, manages access control, and handles retention policies, allowing the system to serve itself and eliminating the need for manual file management operations.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces manual mechanical file management operations with an automated server-based system. Instead of manually creating and managing files, the system uses server processes to automatically generate files from templates, store them, manage access control, and enforce retention policies, substituting human operations with automated computational processes.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If traditional server file storage is used, then files can be stored and accessed, but security and access control are insufficient

Engineering Contradiction:
Improveaccess control securityVSAvoidaccess validation mechanism complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an identity provider as an intermediary between the server and the user authentication process. The identity provider validates user identities and issues authentication information to the server, adding a layer of security without requiring the server to directly manage complex authentication logic. This intermediary handles the complexity of identity validation while maintaining secure access control.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The access control system is segmented into separate functional components: the server handles file storage and URI generation, while the identity provider handles authentication and authorization. This segmentation allows each component to focus on specific security functions, improving overall security without requiring a single complex system to handle all security requirements.

Inventive Principle:
Principle #1Segmentation

3Reliability

If comprehensive access validation is implemented, then security is enhanced, but system complexity increases

Engineering Contradiction:
Improveidentity validation accuracyVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The identity provider serves as an intermediary that handles complex identity validation tasks. Instead of the server directly implementing complex authentication logic, the identity provider performs these validation functions and returns authentication information to the server, reducing the complexity burden on the server while maintaining high validation accuracy.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The identity provider is designed as a universal authentication service that can validate various types of user identities and provide authentication information to multiple servers. This multi-functional approach consolidates authentication complexity into a single reusable service, improving validation accuracy without requiring each individual server to implement complex authentication logic.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20250294028A1Methods and systems for user authentication and file access control
Publication Date: 2025.09.18 INKIT WORLDWIDE LLC
  • US20250294028A1 patent drawing
  • US20250294028A1 patent drawing
  • US20250294028A1 patent drawing

AI summary

The present disclosure relates to methods for administering access to generated files. The method involves storing a file on a server. The server receives a request from a first client device to generate a uniform resource identifier (URI) associated with the file, an identity, and a dynamic expire time. The server generates the URI, which links to a resource comprising the file, and transmits it to a second client device. The server then receives a request from the second client device using the URI to request the resource. The server validates the identity by checking it against a database of authorized identities. Additionally, the server validates the identity through an identity provider, which prompts the user to login to the identity on an identity hosting platform. Based on the response from the server and the identity provider, access to the resource is granted or denied. Based on that access and retention parameters, viewing is allowed, or may be removed if credentials such as viewing time or count is exceeded or biometric scan fail.