Low-Overhead Authority Verification for Distributed Operations

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Computing devices with limited resources face challenges in verifying the authority for operation requests due to the computational expense of traditional certificates and data structures, making them susceptible to malicious attacks and unable to manage operations efficiently.

Innovation Solution

Implementing low overhead certificates and workorders with fixed-size data structures and tokenization to facilitate verification using reduced computing resources, enabling endpoint devices to validate operation requests efficiently.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional certificates and data structures are used for authority verification, then security and authority verification capability are improved, but computational resource consumption increases and device complexity increases

Engineering Contradiction:
Improveauthority verification capabilityVSAvoidcomputational resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent extracts only the essential verification elements from traditional certificates, creating compact verification tokens that contain only the minimum necessary information for authority verification. This extraction reduces computational overhead while maintaining security by focusing on critical verification data only.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

Instead of verifying traditional complex certificates, the patent inverts the approach by using simplified verification tokens that can be quickly validated. The verification mechanism is reversed from certificate-based to token-based, enabling resource-constrained devices to perform verification efficiently.

Inventive Principle:
Principle #13The other way round (Inversion)

2Reliability

If traditional certificates are used for operation verification, then security is improved, but processing speed decreases and computational expense increases

Engineering Contradiction:
ImprovesecurityVSAvoidverification speed
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

The patent creates disposable verification tokens that are computationally inexpensive to generate and verify. These tokens are designed for single-use verification purposes, enabling fast validation without the heavy computational burden of traditional certificates, thus improving verification speed while maintaining security.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Solution Approach 2:

The patent changes the parameters of verification data structures from traditional certificate formats to optimized token formats with different structural characteristics. This parameter change includes using fixed-size structures and simplified validation logic, which significantly improves verification speed while maintaining adequate security through cryptographic signatures.

Inventive Principle:
Principle #35Parameter changes

3Object-affected harmful factors

If comprehensive authority verification is performed, then security against malicious attacks is improved, but device complexity increases and resource requirements increase

Engineering Contradiction:
Improveprotection against malicious attacksVSAvoidverification system complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent segments the authority verification process into distinct components: token generation, token validation, and authority checking. This segmentation allows each component to be optimized independently, reducing overall system complexity while maintaining comprehensive security checks against malicious attacks through layered verification.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces verification tokens as intermediary objects between the operation requester and the authority verification system. These tokens act as mediators that encapsulate verification data, simplifying the interaction and reducing system complexity while maintaining robust security through the token-based verification mechanism.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If traditional verification methods are used, then authority validation capability is improved, but processing time increases and computational cost increases

Engineering Contradiction:
Improveauthority validation capabilityVSAvoidverification processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs preliminary actions by pre-generating verification tokens with embedded authority information before operations are executed. This preliminary preparation allows for rapid verification during operation execution, reducing verification processing time while maintaining authority validation capability through pre-computed cryptographic elements.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12413422B2System and method for efficient verification of authority for invocation of operations
Publication Date: 2025.09.09 DELL PROD LP
  • US12413422B2 patent drawing
  • US12413422B2 patent drawing
  • US12413422B2 patent drawing

AI summary

Methods and systems for verifying authority in distributed systems are disclosed. Authority may be delegated to various entities within a distributed system to invoke performance of operations within the distributed systems. To verify that authority has been delegated, a security framework may be used that limits computing resource consumption for the verifications. The computing resource consumption may be limited by using cryptographically verifiable data structures that establish chains of delegation of authority. The cryptographically verifiable data structures may be limited in size and content to reduce the computational cost for implementing the security framework.