Multi-Credential Access Control via Threshold Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current access control systems relying on user credentials are rigid and restrictive, leading to frustration for both designers and users, as they limit flexibility in managing access to resources.

Innovation Solution

A system that collects and verifies multiple user credentials, comparing them to a threshold combination to determine access permission, allowing access based on a combination of credentials from various users, including the requesting user and others, with options for different verification methods and risk assessments.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If traditional user credentials are used for access control, then access security is maintained, but system flexibility and ease of operation deteriorate

Engineering Contradiction:
Improveaccess control flexibilityVSAvoiduser operation convenience
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent segments the access control system into multiple independent credential sources (requesting user credentials, additional user credentials, device identifiers, location data) that can be independently verified and combined. This segmentation allows flexible configuration of access policies without requiring changes to the core authentication mechanism, thereby improving adaptability while maintaining operational simplicity through modular verification steps.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system implements a universal access control framework that can handle multiple types of credentials and verification methods (user authentication, device identification, location verification) through a single unified process. This multi-functional approach allows the same system to accommodate various access scenarios (single user, multiple users, device-based access, location-based access) without requiring separate systems, thus enhancing flexibility while preserving ease of operation.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If multiple user credentials are collected and verified, then access control flexibility improves, but system complexity increases

Engineering Contradiction:
Improveaccess control flexibilityVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent divides the credential verification process into distinct sequential stages: collecting requesting user credentials, collecting additional user credentials, verifying each credential type, and making access determinations. This segmentation of the verification process into manageable, independent steps reduces system complexity by allowing each verification stage to be implemented and tested separately, while still achieving flexible multi-credential access control.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system introduces an intermediary access control service that mediates between multiple credential sources and the resource being accessed. This intermediary layer handles the complexity of collecting, verifying, and evaluating multiple credentials, shielding the resource system from direct complexity while enabling flexible access policies. The intermediary translates diverse credential inputs into standardized verification outcomes.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8904509B2Resource access based on multiple credentials
Publication Date: 2014.12.02 MICROSOFT TECHNOLOGY LICENSING LLC
  • US8904509B2 patent drawing
  • US8904509B2 patent drawing
  • US8904509B2 patent drawing

AI summary

A collection of multiple user credentials each associated with one of multiple different users is obtained at a device, and one or more of the multiple user credentials are verified. A determination is made as to whether access to a resource is permitted, by at least comparing the collection of multiple user credentials to a threshold combination of user credentials to be satisfied to access the resource. An indication of whether access to the resource by a requesting user is permitted is returned or provided to another device.