Invitation Link Access Control for Secure Network Services

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network services are vulnerable to cybercrimes due to unauthorized access, which compromises private information and sensitive data.

Innovation Solution

An optimized access control system is implemented, where an infrastructure device transmits an invitation link to a user device, followed by seed information to determine authentication information, enabling secure communication sessions and authenticating user requests.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional network access control is used, then network services can be provided, but the system is vulnerable to unauthorized access and cybercrimes

Engineering Contradiction:
ImprovesecurityVSAvoidaccess control mechanism
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system performs preliminary authentication actions by establishing secure communication channels and verifying device identities before allowing network service access. The infrastructure device validates the user device's credentials and establishes cryptographic contexts in advance, preventing unauthorized access attempts from compromising the network.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces cryptographic intermediaries including authentication contexts, cryptographic contexts, and signed tokens that mediate between the user device and infrastructure device. These intermediaries verify identities and authenticate requests without requiring direct trust between communicating parties, thereby enhancing security while maintaining manageable complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If authentication information is transmitted securely, then unauthorized access is prevented, but communication overhead increases

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication process time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary authentication during the initial connection establishment, creating cryptographic contexts and signing tokens in advance. Once authenticated, the user device can make subsequent requests without repeating the full authentication process, reducing time loss for legitimate users while maintaining strong security.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The authentication mechanism dynamically adapts to different communication scenarios. The infrastructure device verifies cryptographic contexts and signed tokens with varying levels of scrutiny based on the request type and communication session state, optimizing the balance between security verification and processing speed.

Inventive Principle:
Principle #15Dynamics

3Reliability

If session-based authentication is implemented, then continuous secure communication is enabled, but session management complexity increases

Engineering Contradiction:
Improvecontinuous authenticationVSAvoidsession management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The cryptographic context serves multiple functions simultaneously: it establishes encrypted communication channels, verifies device identities, and provides the basis for signing subsequent requests. This multi-functionality reduces session management complexity by consolidating authentication state into a single versatile data structure that the infrastructure device can verify without maintaining separate session records.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20250047662A1Optimized access control system
Publication Date: 2025.02.06 UAB 360 IT
  • US20250047662A1 patent drawing
  • US20250047662A1 patent drawing
  • US20250047662A1 patent drawing

AI summary

The present disclosure discloses configuring a user device to receive an invitation link to enable the user device to receive network services from an infrastructure device; configuring the user device to receive, based on the user device activating the invitation link, seed information to be utilized by the user device to determine authentication information; configuring the user device to transmit, during an active communication session and based on determining the authentication information, a user request related to an action to be performed regarding receiving the network services, a portion of the user request being signed based on utilizing a first portion of the authentication information; and configuring the user device to perform the action regarding receiving the network services based on a verification that the communication session is currently active. Various other aspects are contemplated.