Bulk Licensing Identity Segmentation for Device Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current bulk licensing systems face challenges in managing access and security, including unauthorized token use, limited control over license allocation, and human errors in global token management, which compromise security and complexity.
Innovation Solution
The implementation of licensing identities and tenant identities within device management systems to manage access and perform license operations, reducing security risks and complexity by using preconfigured lists and shared authentication credentials, allowing granular access control and simplifying operations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If global tokens are used for access control in bulk licensing systems, then access management is simplified, but security is compromised due to unauthorized token use and human errors in token management
Solution Approach 1:
The patent segments the monolithic global token into multiple individual tokens, each associated with a specific device management system. This segmentation allows each token to have limited scope and validity, improving security while maintaining ease of access management. The bulk licensing system can issue different tokens to different device management systems, and each token can be independently managed and revoked without affecting others.
Solution Approach 2:
The patent implements local quality by making each token specific to a particular device management system rather than creating a universal global token. Each token has localized permissions and validity scope tied to its issuing system. This allows the bulk licensing system to apply different security policies and access controls to different device management systems, improving overall security while maintaining operational simplicity through automated token distribution.
2Ease of operation
If manual global token management is implemented, then access control is established, but human errors occur and security is compromised
Solution Approach 1:
The patent implements self-service by enabling device management systems to automatically receive and manage their own tokens through the bulk licensing system. The system automatically issues tokens to device management systems that register with the bulk licensing system, eliminating manual token distribution. Device management systems can independently manage their tokens, request new ones, and have them automatically revoked when no longer needed, removing human error from the equation while maintaining easy access control.
3Reliability
If a centralized bulk licensing system is used, then license allocation control is improved, but system complexity increases
Solution Approach 1:
The patent extracts the token management functionality from the bulk licensing system and places it in the device management systems themselves. Each device management system maintains its own tokens locally and uses them to authenticate with the bulk licensing system. This extraction reduces the operational complexity of the centralized system while maintaining its ability to control license allocation, as the complexity of token distribution and management is distributed to the edge devices rather than concentrated in the central system.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
The present disclosure involves systems, software, and computer-implemented methods for managing access of device management systems in license management operations associated with purchase accounts of a bulk licensing system. An example method includes identifying a request for a license management operation associated with a purchase account of a bulk licensing system, wherein the request includes a licensing identity associated with the purchase account; in response to the identifying, determining that the license management operation is to be performed based on the licensing identity; and in response to the determining, performing the license management operation.