Multi-Party Authorization System for Near Real-Time Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current computer system security techniques, such as password-based access and biometric authentication, are prone to errors and unauthorized access due to their complexity and susceptibility to theft, and there is a need for a method to prevent a single authorized individual from compromising the system without disrupting normal operations.
Innovation Solution
A networked computer system that requires multiple parties to authorize tasks before access is granted, utilizing a policy engine to determine restricted resources and authorizers, ensuring simultaneous approval in near real-time through an authorization server and agent infrastructure.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If multiple party authorization is required for access, then security is improved, but system complexity and approval time increase
Solution Approach 1:
The authorization system is segmented into distinct components: policy definition modules, authorization request handlers, party notification systems, and approval aggregation logic. This segmentation allows each component to be independently managed and optimized, reducing overall system complexity while maintaining multi-party authorization capabilities
Solution Approach 2:
An intermediary authorization service is introduced that mediates between resource requesters and multiple authorizing parties. This intermediary abstracts the complexity of coordinating multiple approvals, managing party communications, and aggregating decisions, thereby simplifying the overall system architecture
2Reliability
If multiple parties must approve access requests, then unauthorized access is prevented, but access time and operational efficiency decrease
Solution Approach 1:
The system performs preliminary actions by pre-identifying required authorizing parties, pre-notifying them of upcoming authorization requests, and pre-establishing authorization policies. This allows parties to be mentally prepared and available for quick approval when requests occur, reducing actual approval time
Solution Approach 2:
Authorizing parties are empowered to self-manage their authorization preferences, availability settings, and delegated authorization rules. This self-service capability reduces administrative overhead and enables faster automated authorization decisions based on pre-configured party preferences and availability
3Reliability
If simultaneous approval from multiple parties is required, then security against compromised credentials is improved, but system disruption increases
Solution Approach 1:
The authorization system dynamically adjusts its operation based on real-time conditions: it can switch between requiring simultaneous approvals and allowing sequential approvals based on resource criticality, party availability, and operational context. This dynamic behavior maintains security while minimizing disruption to normal operations
Solution Approach 2:
The system changes key parameters such as the number of required approvals, the simultaneity requirement, and party selection based on resource sensitivity levels and operational conditions. For critical resources, stricter simultaneous multi-party approval is enforced, while for less critical resources, more flexible approval processes are applied, balancing security with operational continuity
Data Source
AI summary
A method and apparatus are used in determining authorization to perform tasks in a computer environment, and specifically requiring multiple parties to authorize a task before access is granted. The present system provides for substantially real time communication to a second party authorizer when a task owner is attempting to perform a task.


