Exposed Service Access Management for Dynamic Application Authorization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In container-based edge computing ecosystems, existing systems lack the ability to automatically and dynamically assign access permissions to exposed services for entire applications, leading to arbitrary and uncontrolled access privileges being granted by application providers, which can compromise security and resource management.

Innovation Solution

A system with a management unit and access authorization determination unit dynamically assigns access rights to exposed services based on predefined policies, ensuring that access permissions are adapted to the current application and environment, preventing unauthorized access and optimizing resource usage.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If application providers manually assign access privileges to exposed services, then application deployment is simple and flexible, but security control is lost and arbitrary access permissions are granted

Engineering Contradiction:
Improveapplication deployment simplicityVSAvoidsecurity control
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces an orchestrator as an intermediary between application providers and exposed services. The orchestrator automatically manages service account creation, access token generation, and permission assignment based on predefined policies, eliminating the need for application providers to manually assign privileges while maintaining security control through centralized authorization management

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If centralized access management is implemented using traditional RBAC, then security is improved, but manual configuration complexity increases and automation is reduced

Engineering Contradiction:
ImprovesecurityVSAvoidconfiguration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system enables self-service automation where the orchestrator automatically creates service accounts, generates access tokens, and assigns permissions to container instances based on their identity and predefined policies. This eliminates manual RBAC configuration while maintaining security, as the system autonomously manages the entire authorization lifecycle without operator intervention

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent implements preliminary action by pre-configuring authorization policies and service account templates before applications are deployed. The orchestrator uses these pre-established configurations to automatically grant appropriate permissions during application deployment, eliminating the need for manual post-deployment configuration and reducing operational complexity

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If application providers are given full access control, then deployment flexibility is maximized, but unauthorized access and security risks increase

Engineering Contradiction:
Improvedeployment flexibilityVSAvoidunauthorized access risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent changes the authorization model from static provider-defined permissions to dynamic orchestrator-managed permissions. The system automatically adjusts access parameters (service account credentials, token scopes, expiration times) based on the specific container instance identity and predefined security policies, maintaining deployment flexibility while eliminating unauthorized access risks through automated parameter optimization

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentEP4610864A1System for managing access rights to exposed services
Publication Date: 2025.09.03 SIEMENS AG
  • EP4610864A1 patent drawingFigure 1~2
  • EP4610864A1 patent drawingFigure 3
  • EP4610864A1 patent drawingFigure 4

AI summary

The invention relates to a system (S) for managing access authorizations to exposed services (ED). The system (S) comprises a management unit (VE) for managing access authorizations, at least one exposed service (ED), and an access authorization determination unit (ZBE). The management unit (VE) is configured to receive a request to start an overall application (GA) consisting of at least one component (CI). The overall application (GA) has a description file required for starting, which includes at least one reference to the at least one exposed service (ED). The management unit (VE) is further configured to request access authorization to the at least one exposed service (ED) for the overall application (GA) from the access authorization determination unit (ZBE).Obtain application- and/or environment-specific access authorization from the access authorization determination unit (AAU) and start the overall application (GA) using the obtained access authorization. This system makes it possible to dynamically and centrally grant access authorizations to overall applications based on the current application- and environment-specific conditions.