Guest Workspace Segmentation for Secure Digital Asset Sharing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The subscription model for online storage services (SaaS) makes it difficult for non-subscribers to access digital assets without sharing the subscriber's credentials, potentially leading to malicious use of excessive privileges.

Innovation Solution

A resource server generates temporary guest credentials for non-subscribers, allowing them to access a guest workspace with limited privileges, preventing access to the subscriber's workspace and reducing the risk of malicious activities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a non-subscriber is given access to a subscriber's workspace to share digital assets, then the non-subscriber can access and upload files, but the non-subscriber receives the same privileges as the subscriber which can be used for malicious purposes

Engineering Contradiction:
Improvenon-subscriber access to digital assetsVSAvoidmalicious use of excessive privileges
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The workspace is segmented into a guest workspace and a subscriber workspace. The guest workspace is a separate, isolated environment that allows non-subscribers to access and upload files without gaining access to the subscriber's main workspace or credentials. This segmentation enables limited access while preventing harmful actions against the subscriber's account.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A guest workspace acts as an intermediary between the non-subscriber and the subscriber's digital assets. The guest workspace provides a temporary, limited-access environment where non-subscribers can perform file operations without directly interacting with or accessing the subscriber's credentials or full workspace, thus preventing malicious use of privileges.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If the subscriber logs in to the non-subscriber's computing device to allow file upload, then the non-subscriber can access the digital asset, but the subscriber's credentials are shared which creates security risks

Engineering Contradiction:
Improvenon-subscriber access to digital assetVSAvoidsecurity of subscriber credentials
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

Instead of sharing the subscriber's credentials, the system creates a copy of the workspace environment called a guest workspace. This guest workspace is a virtual copy that replicates the necessary functionality for file access and upload without containing or requiring the subscriber's actual credentials. The non-subscriber interacts with this copy, not the original subscriber account.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The guest workspace serves as an intermediary layer that prevents direct exposure of subscriber credentials. The non-subscriber accesses files through this intermediary workspace, which translates their operations into safe, limited-scope actions that do not require or reveal the subscriber's authentication information.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If guest credentials are generated with full subscriber privileges, then the non-subscriber can access all digital assets, but the provider cannot protect against unauthorized access to subscriber accounts

Engineering Contradiction:
Improvenon-subscriber access flexibilityVSAvoidprovider protection against unauthorized access
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system segments access rights by creating a separate guest workspace that is distinct from the subscriber workspace. The guest workspace is configured with specific, limited privileges that allow file access and upload operations but explicitly exclude access to subscriber credentials, account settings, and other protected resources. This segmentation maintains versatility for legitimate sharing while enforcing provider protection.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The guest workspace has local quality characteristics that differentiate it from the subscriber workspace. It provides a localized environment with specific permissions tailored to file access operations only, rather than full system access. This local quality ensures that non-subscribers receive necessary access flexibility for their specific task while the provider maintains protection over sensitive subscriber account areas.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS8826373B2Methods and systems for sharing digital assets
Publication Date: 2014.09.02 SHARP KK
  • US8826373B2 patent drawing
  • US8826373B2 patent drawing
  • US8826373B2 patent drawing

AI summary

Aspects of the present invention relate to systems and methods for providing non-subscriber access to a digital asset and, in particular, to methods and systems for providing non-subscriber access to a digital asset while providing provider protection. A temporary guest credential may be generated that may allow access to a limited workspace on a resource server. The temporary guest credentials may expire after a guest-account duration limit.