Intermediary Device Broker Service Access via Kerberos Tickets

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems face challenges in granting limited access to service devices, such as vehicles or garage doors, to individuals who do not possess the control device, necessitating a solution for secure and controlled access management.

Innovation Solution

A networking architecture that utilizes an intermediary device to broker limited access by communicating with a control device and a service device, employing Kerberos protocol for authentication and ticket distribution, allowing access through an access ticket transmitted via the intermediary device.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If access to a service device is limited only to those possessing a control device, then security and control are maintained, but accessibility is reduced for legitimate users who do not have the control device

Engineering Contradiction:
ImproveaccessibilityVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces an intermediary device that acts as a mediator between the control device and the service device. The intermediary receives requests from users without control devices, communicates with the control device to obtain authorization, and then facilitates access to the service device. This resolves the contradiction by enabling accessibility for users without control devices while maintaining security through the intermediary's coordination with the control device.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If an intermediary device is introduced to broker access requests, then accessibility is improved for users without control devices, but system complexity increases

Engineering Contradiction:
ImproveaccessibilityVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The intermediary device is designed to perform multiple functions: receiving access requests from various users, communicating with the control device, managing authentication, and coordinating service device access. By consolidating these diverse functions into a single multi-functional intermediary, the system achieves improved accessibility without proportionally increasing overall system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Adaptability or versatility

If limited access is brokered through an intermediary device, then controlled access is enabled for authorized users, but the time required for access authorization increases

Engineering Contradiction:
Improveaccess control capabilityVSAvoidauthorization time
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by having the intermediary device pre-establish communication channels with the control device and pre-validate access requests against authorization criteria. The intermediary can quickly determine whether to forward requests to the control device based on pre-configured access policies, reducing the time required for authorization while maintaining controlled access capability.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10417852B2Providing limited access to a service device via an intermediary
Publication Date: 2019.09.17 TAHOE RES LTD
  • US10417852B2 patent drawing
  • US10417852B2 patent drawing
  • US10417852B2 patent drawing

AI summary

Systems and methods may provide for brokering limited access to a service device via an intermediary. In one example, the method may include receiving a request communication at a control device including a request for limited access to a service device, wherein the request is received from an intermediary device on behalf of a request device, and transmitting an access communication to the intermediary device, wherein the access communication includes an access ticket to be used by the request device to gain the limited access of the service device.