Multiparty Authorization for Resource Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Administrators in systems or networks have excessive power, leading to potential accidental deletion of critical data or unauthorized access to sensitive information, compromising system security due to administrative mistakes or malicious actions.
Innovation Solution
Implementing multiparty authorization, where access to resources requires authorization from multiple parties, using access control metadata and token-based systems to ensure that no single individual can operate on a resource without consensus from all authorized parties, thereby preventing administrative errors and malicious access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If administrators are given extensive access rights to manage resources, then system management capability is improved, but system security deteriorates due to potential accidental deletion or unauthorized access
Solution Approach 1:
The patent segments administrative authority by introducing a multiparty authorization system where access rights are divided among multiple administrators. Instead of giving one administrator complete control, the system requires multiple administrators to jointly authorize sensitive operations, thereby segmenting the power and reducing the risk of single-point failures or malicious actions.
Solution Approach 2:
The patent implements preliminary action by requiring pre-authorization from multiple administrators before sensitive operations can be executed. The system预先 (in advance) establishes authorization policies and requires multiple approvals before critical actions such as deleting encryption keys or accessing sensitive data, preventing hasty or malicious operations.
2Productivity
If single administrator control is used for resource access, then operational efficiency is improved, but reliability deteriorates due to single-point failures
Solution Approach 1:
The patent segments the single point of control into multiple authorization points. By requiring multiple administrators to approve sensitive operations, the system eliminates single-point failures where one compromised or erroneous administrator could cause system compromise. The segmentation of authority improves reliability while maintaining operational efficiency through automated workflows.
3Object-affected harmful factors
If multiparty authorization is implemented, then system security is improved, but device complexity increases due to multiple authorization requirements
Solution Approach 1:
The patent introduces an intermediary authorization system that mediates between multiple administrators and resources. This intermediary layer automatically manages the complexity of multiparty authorization by handling policy evaluation, authorization requests, and coordination among administrators, thereby improving security while abstracting away the complexity from users.
Solution Approach 2:
The patent applies parameter changes by dynamically adjusting authorization requirements based on the sensitivity of resources and types of operations. Instead of applying uniform multiparty authorization to all operations, the system changes authorization parameters (such as number of required approvers) based on risk levels, resource criticality, and operation types, thereby improving security for critical operations while minimizing complexity for routine tasks.
Data Source
AI summary
The subject disclosure is generally directed towards an automated mechanism in a computer network or system that controls resource access to any resource designated as needing multiparty authorization. In one aspect, a resource that needs multiparty authorization before access is allowed is identified, along with policy that specifies an authorizer (or multiple authorizers) for the resource. An access control list may contain metadata that indicates the need for multiparty authorization. Authorization may be provided via a token, which may be cached for future use.


