Guest Workspace Segmentation for Secure Digital Asset Sharing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The subscription model for online storage services (SaaS) makes it difficult for non-subscribers to access digital assets without sharing the subscriber's credentials, potentially leading to malicious use of excessive privileges.
Innovation Solution
A resource server generates temporary guest credentials for non-subscribers, allowing them to access a guest workspace with limited privileges, preventing access to the subscriber's workspace and reducing the risk of malicious activities.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a non-subscriber is given access to a subscriber's workspace to share digital assets, then the non-subscriber can access and upload files, but the non-subscriber receives the same privileges as the subscriber which can be used for malicious purposes
Solution Approach 1:
The workspace is segmented into a guest workspace and a subscriber workspace. The guest workspace is a separate, isolated environment that allows non-subscribers to access and upload files without gaining access to the subscriber's main workspace or credentials. This segmentation enables limited access while preventing harmful actions against the subscriber's account.
Solution Approach 2:
A guest workspace acts as an intermediary between the non-subscriber and the subscriber's digital assets. The guest workspace provides a temporary, limited-access environment where non-subscribers can perform file operations without directly interacting with or accessing the subscriber's credentials or full workspace, thus preventing malicious use of privileges.
2Ease of operation
If the subscriber logs in to the non-subscriber's computing device to allow file upload, then the non-subscriber can access the digital asset, but the subscriber's credentials are shared which creates security risks
Solution Approach 1:
Instead of sharing the subscriber's credentials, the system creates a copy of the workspace environment called a guest workspace. This guest workspace is a virtual copy that replicates the necessary functionality for file access and upload without containing or requiring the subscriber's actual credentials. The non-subscriber interacts with this copy, not the original subscriber account.
Solution Approach 2:
The guest workspace serves as an intermediary layer that prevents direct exposure of subscriber credentials. The non-subscriber accesses files through this intermediary workspace, which translates their operations into safe, limited-scope actions that do not require or reveal the subscriber's authentication information.
3Adaptability or versatility
If guest credentials are generated with full subscriber privileges, then the non-subscriber can access all digital assets, but the provider cannot protect against unauthorized access to subscriber accounts
Solution Approach 1:
The system segments access rights by creating a separate guest workspace that is distinct from the subscriber workspace. The guest workspace is configured with specific, limited privileges that allow file access and upload operations but explicitly exclude access to subscriber credentials, account settings, and other protected resources. This segmentation maintains versatility for legitimate sharing while enforcing provider protection.
Solution Approach 2:
The guest workspace has local quality characteristics that differentiate it from the subscriber workspace. It provides a localized environment with specific permissions tailored to file access operations only, rather than full system access. This local quality ensures that non-subscribers receive necessary access flexibility for their specific task while the provider maintains protection over sensitive subscriber account areas.
Data Source
AI summary
Aspects of the present invention relate to systems and methods for providing non-subscriber access to a digital asset and, in particular, to methods and systems for providing non-subscriber access to a digital asset while providing provider protection. A temporary guest credential may be generated that may allow access to a limited workspace on a resource server. The temporary guest credentials may expire after a guest-account duration limit.


