Multi-factor Execution Gateway for Secure Process Automation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current processes for executing tasks in restricted or protected environments are cumbersome, requiring users to seek approval from multiple peers and triage personnel, leading to bottlenecks and inefficiencies, especially in large-scale operations where direct access is limited.

Innovation Solution

Implementing a multi-factor execution gateway that generates a unique key based on request parameters and authorization levels, allowing users to execute processes directly in target environments while ensuring security and compliance by obtaining necessary approvals through a public-private key signing mechanism.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If users contact multiple peers and triage personnel for approval before executing processes, then security and compliance are ensured, but execution time and operational efficiency deteriorate

Engineering Contradiction:
Improvesecurity and complianceVSAvoidexecution time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-establishing authorization rules, fingerprints, and approval workflows before process execution is needed. Authorization decisions are pre-configured based on process parameters, user roles, and security policies, allowing the system to automatically evaluate and approve requests without requiring real-time human intervention for routine operations.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary authorization system that acts as a mediator between users and the target environment. This system uses pre-configured rules, fingerprints, and automated workflows to evaluate authorization requests, reducing the need for direct human-to-human approval chains while maintaining security and compliance through systematic evaluation.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If users are granted direct access to execute processes in restricted environments, then operational efficiency improves, but security control deteriorates

Engineering Contradiction:
Improveoperational efficiencyVSAvoidsecurity control
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system enables self-service by allowing users to independently execute processes after initial authorization configuration. Users can submit authorization requests with process parameters, and the system automatically evaluates these requests against pre-configured rules, fingerprints, and approval workflows, enabling users to perform operations without manual intervention from operations personnel.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent applies parameter changes by dynamically adjusting authorization decisions based on process parameters, user roles, target environments, and security policies. The system evaluates multiple parameters including process type, target system, user credentials, and pre-configured approval requirements to make contextual authorization decisions that balance security control with operational efficiency.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If multiple approval layers are implemented for process execution, then authorization security improves, but device and process complexity increases

Engineering Contradiction:
Improveauthorization securityVSAvoidprocess complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments the authorization process into distinct components: fingerprint generation from process parameters, rule-based evaluation, automated workflow routing, and approval decision-making. This segmentation allows complex multi-factor authorization to be broken down into manageable, modular steps that can be independently configured and maintained, reducing overall system complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements a universal authorization framework that handles multiple process types, user roles, and security requirements through a single integrated system. The same authorization mechanism evaluates diverse requests by adjusting parameters such as process fingerprint, user credentials, and approval workflows, eliminating the need for separate authorization systems for different scenarios and reducing cumulative complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10574638B2Multi-factor execution gateway
Publication Date: 2020.02.25 MICROSOFT TECHNOLOGY LICENSING LLC
  • US10574638B2 patent drawing
  • US10574638B2 patent drawing
  • US10574638B2 patent drawing

AI summary

A user may desire to execute a process in a target environment. However, administrators may want control over processes that haven't been preapproved to prevent the execution of processes that may affect security and compliance within the environment. Implementation of a multi-factor execution gateway may grant the user limited access to execute the process himself at an otherwise restricted, protected, or decoupled environment, while ensuring security and compliance by obtaining approval from the appropriate authorities. For example, a request to execute the process in the environment may be detected, and a fingerprint may be generated based on parameters of the request. A signature for the fingerprint in the form of private key(s) acquired from authorizer(s) based on a level of authorization required for the process may be received to generate a key, and execution of the process may then be allowed at the environment using the key.