Identity Firewall Attribute-Based Authorization Mobile Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network computing and storage solutions lack efficient mechanisms for dynamic authorization, authentication, and routing of resources for mobile devices, particularly in scenarios where multiple personas or identities need to access and manage different types of data and applications on-demand.

Innovation Solution

Implementing an identity firewall that performs attribute-based authorization and routing, allowing for the consolidation of traffic, dynamic determination of authorization and authentication based on attributes, and the use of companion and container instances to manage mobile device resources, enabling efficient access and management of resources across various personas and applications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If traditional network computing solutions are used, then basic resource access is provided, but dynamic authorization and authentication for multiple personas is inefficient

Engineering Contradiction:
Improvedynamic authorization capabilityVSAvoidresource access efficiency
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The system implements dynamic authorization by determining access rights at runtime based on request attributes rather than static pre-configured permissions. The identity firewall evaluates attributes such as user identity, device characteristics, and request context to dynamically grant or deny access, enabling adaptable security policies that respond to changing conditions without requiring manual reconfiguration.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The authorization mechanism changes parameters by evaluating multiple attributes of the request (user identity, device type, location, time) and making access decisions based on combinations of these parameters. This allows the system to provide different levels of access for different personas and contexts, improving both adaptability and efficiency compared to traditional single-parameter authentication.

Inventive Principle:
Principle #35Parameter changes

2Adaptability or versatility

If multiple personas access different data and applications, then functionality is enhanced, but system complexity increases

Engineering Contradiction:
Improvemulti-persona supportVSAvoidauthorization system complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system segments the authorization process into distinct components: attribute extraction, policy evaluation, and access decision. The identity firewall separates concerns by handling authentication, authorization, and routing as independent functions. This segmentation manages complexity by organizing the multi-persona support into modular, manageable pieces rather than a monolithic system.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The identity firewall acts as an intermediary between resources and requestors, mediating all access requests. It evaluates attributes and policies without requiring complex configuration in the underlying resources or client devices. This intermediary approach simplifies the overall system by centralizing the complexity management in a dedicated component that handles multi-persona authorization transparently.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If attribute-based routing is implemented, then request routing efficiency is improved, but processing overhead increases

Engineering Contradiction:
Improverequest routing efficiencyVSAvoidattribute evaluation time
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The system performs preliminary action by pre-configuring policy rules and attribute evaluation criteria in the identity firewall. Rather than creating complex routing logic at runtime, the policies are established in advance, allowing the firewall to efficiently evaluate requests against predetermined criteria. This reduces processing time during actual request handling while maintaining routing efficiency.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10911404B1Attribute based authorization
Publication Date: 2021.02.02 AMAZON TECH INC
  • US10911404B1 patent drawing
  • US10911404B1 patent drawing
  • US10911404B1 patent drawing

AI summary

A service provider may provide a plurality of companion instances associated with a mobile device in order to facilitate operation of the mobile device. The companion instances and the mobile device may be configured to execute various components of one or more application. Furthermore, an identity firewall may be provided to authorize and route network traffic to the plurality of companion instances based at least in part one or more attributes of the network traffic.