Conditional Permission Delegation via Credential Constraints

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems lack an efficient method for delegating permissions associated with credentials in a controlled and conditional manner, particularly in terms of geographic and temporal constraints, which can lead to misuse or unauthorized access.

Innovation Solution

A system that allows users to delegate permissions by associating them with conditions, such as geographic or temporal restrictions, by modifying existing credentials or creating new ones, using representations like QR codes for validation, ensuring that permissions are only usable when conditions are met.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If permissions are delegated without conditions, then ease of operation is improved, but security and control deteriorate

Engineering Contradiction:
Improvepermission delegationVSAvoidsecurity control
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent applies parameter changes by introducing conditional parameters (geographic location, time of day, duration) to the permission delegation process. The credential system dynamically adjusts permission validity based on these parameters, allowing easy delegation while maintaining security through conditional constraints on when and where permissions can be exercised.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If geographic and temporal constraints are added to permissions, then security is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity controlVSAvoidcredential system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements nesting by embedding multiple layers of constraints within the credential structure. Geographic围栏, temporal restrictions, and duration limits are nested within the permission framework, allowing the system to maintain a unified credential interface while incorporating complex security conditions without proportionally increasing operational complexity.

Inventive Principle:
Principle #7Nested doll (Nesting)

3Adaptability or versatility

If permissions are made transferable to other users, then adaptability is improved, but control and authorization deteriorate

Engineering Contradiction:
Improvepermission transferabilityVSAvoidauthorization control
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent uses the credential as an intermediary that mediates permission transfer between users. The credential system acts as a trusted intermediary that verifies and enforces authorization rules during transfer, enabling adaptable permission sharing while maintaining centralized control and authorization integrity through the credential validation mechanism.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10237278B1Permission delegation technology
Publication Date: 2019.03.19 STRATEGY INC
  • US10237278B1 patent drawing
  • US10237278B1 patent drawing
  • US10237278B1 patent drawing

AI summary

In one implementation, a computer system maintains one or more permissions associated with a credential held by a first user, where at least one of the one or more of permissions is delegatable by the first user to one or more other users. The computer system receives an indication that the first user has chosen to delegate a particular permission from amongst the one or more permissions to a second user, wherein the particular permission is needed to perform a particular type of action. Based on the first user indicating a choice to delegate the particular permission to the second user, the computer system associates the delegation of the particular permission with the second user. Based on delegating the particular permission with the second user, the computer system enables the second user to perform the particular type of action.