Resource Access Gateway Credential Mediation for Secure Retrieval

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for accessing resources remotely are vulnerable to credential interception and require frequent communication of multiple credentials, leading to inefficiency and unreliability due to bandwidth and power consumption, as well as potential failures or corruptions of single sources.

Innovation Solution

A resource access gateway (RAG) manages credentials by receiving a first credential, obtaining a second credential from a storage medium, generating electronic authorizations, and using these to securely access resources from multiple sources, with backup authorizations and redundancy to ensure reliability and efficiency.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If multiple credentials are communicated frequently for remote resource access, then access flexibility is improved, but security deteriorates due to credential interception risk

Engineering Contradiction:
Improveaccess flexibilityVSAvoidcredential interception risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system segments credentials into multiple parts and distributes them across different sources. Instead of transmitting complete credentials frequently, the system uses credential tokens that reference segmented credential parts stored at different locations, reducing the risk of complete credential interception while maintaining access flexibility.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary credential management system that mediates between the resource requester and resource sources. This intermediary handles credential segmentation, storage, and reassembly, allowing flexible access without direct transmission of complete credentials, thereby reducing interception risk.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If multiple credentials are transmitted frequently, then access capability is improved, but bandwidth consumption increases

Engineering Contradiction:
Improveaccess capabilityVSAvoidbandwidth consumption
Core Design Contradiction:
Adaptability or versatilityVSLoss of energy

Solution Approach 1:

Instead of transmitting actual credentials frequently, the system transmits lightweight credential tokens that reference the segmented credential parts stored at different sources. These tokens are small in size and can be transmitted efficiently, reducing bandwidth consumption while maintaining access capability.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The system performs preliminary segmentation and distribution of credentials to multiple sources before access is needed. This preliminary action allows subsequent access requests to use pre-positioned credential parts, eliminating the need for frequent transmission of large credential data and reducing bandwidth consumption.

Inventive Principle:
Principle #10Preliminary action

3Device complexity

If a single source is used for resource access, then system complexity is reduced, but reliability deteriorates due to potential failures or corruptions

Engineering Contradiction:
Improvesystem complexityVSAvoidaccess reliability
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The system segments the credential storage across multiple sources rather than relying on a single source. Each source holds a segment of the credentials, and the system can retrieve credentials from multiple sources, providing redundancy and improving reliability without significantly increasing system complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements beforehand cushioning by pre-distributing credential segments to multiple sources and establishing backup access paths. If one source fails or becomes corrupted, the system can retrieve credentials from alternative sources, cushioning against failures and maintaining access reliability.

Inventive Principle:
Principle #11Beforehand cushioning (Prior cushioning)

4Ease of operation

If credentials are stored and managed centrally, then ease of operation is improved, but security deteriorates due to single point of failure

Engineering Contradiction:
Improvecredential management easeVSAvoidsecurity resilience
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system segments credential storage across multiple distributed sources rather than using a single centralized storage. This segmentation maintains ease of operation through automated credential management while improving security resilience, as the failure or compromise of one source does not expose all credentials.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements beforehand cushioning by pre-distributing credential segments to multiple sources and establishing backup access paths. If one source fails or becomes corrupted, the system can retrieve credentials from alternative sources, cushioning against failures and maintaining access reliability.

Inventive Principle:
Principle #11Beforehand cushioning (Prior cushioning)

Data Source

PatentUS12423142B2Methods and systems for accessing a resource
Publication Date: 2025.09.23 SHVARTSMAN MICHAEL
  • US12423142B2 patent drawing
  • US12423142B2 patent drawing
  • US12423142B2 patent drawing

AI summary

There is provided a method including receiving, at a resource access gateway (RAG), an electronic request for a given quantity of a resource, and a first credential for accessing a first source of the resource. The first credential may have been input at an input interface in association with the electronic request. The method also includes obtaining a second credential from a credential storing computer-readable storage medium (CRSM) based on the first credential. The second credential may be for accessing a second source of the resource. In addition, the method includes generating at the RAG an electronic authorization for the given quantity to be collected from the second source using the second credential, and sending the electronic authorization to a transfer gateway, which may collect the given quantity from, the second, source, in addition, the method may include outputting a confirmation of access to the given quantity of the resource.