Multiparty Authorization for Resource Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Administrators in systems or networks have excessive power, leading to potential accidental deletion of critical data or unauthorized access to sensitive information, compromising system security due to administrative mistakes or malicious actions.

Innovation Solution

Implementing multiparty authorization, where access to resources requires authorization from multiple parties, using access control metadata and token-based systems to ensure that no single individual can operate on a resource without consensus from all authorized parties, thereby preventing administrative errors and malicious access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If administrators are given extensive access rights to manage resources, then system management capability is improved, but system security deteriorates due to potential accidental deletion or unauthorized access

Engineering Contradiction:
Improvesystem management capabilityVSAvoidsystem security risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent segments administrative authority by introducing a multiparty authorization system where access rights are divided among multiple administrators. Instead of giving one administrator complete control, the system requires multiple administrators to jointly authorize sensitive operations, thereby segmenting the power and reducing the risk of single-point failures or malicious actions.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements preliminary action by requiring pre-authorization from multiple administrators before sensitive operations can be executed. The system预先 (in advance) establishes authorization policies and requires multiple approvals before critical actions such as deleting encryption keys or accessing sensitive data, preventing hasty or malicious operations.

Inventive Principle:
Principle #10Preliminary action

2Productivity

If single administrator control is used for resource access, then operational efficiency is improved, but reliability deteriorates due to single-point failures

Engineering Contradiction:
Improveoperational efficiencyVSAvoidsystem reliability
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent segments the single point of control into multiple authorization points. By requiring multiple administrators to approve sensitive operations, the system eliminates single-point failures where one compromised or erroneous administrator could cause system compromise. The segmentation of authority improves reliability while maintaining operational efficiency through automated workflows.

Inventive Principle:
Principle #1Segmentation

3Object-affected harmful factors

If multiparty authorization is implemented, then system security is improved, but device complexity increases due to multiple authorization requirements

Engineering Contradiction:
Improveunauthorized access preventionVSAvoidauthorization system complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary authorization system that mediates between multiple administrators and resources. This intermediary layer automatically manages the complexity of multiparty authorization by handling policy evaluation, authorization requests, and coordination among administrators, thereby improving security while abstracting away the complexity from users.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent applies parameter changes by dynamically adjusting authorization requirements based on the sensitivity of resources and types of operations. Instead of applying uniform multiparty authorization to all operations, the system changes authorization parameters (such as number of required approvers) based on risk levels, resource criticality, and operation types, thereby improving security for critical operations while minimizing complexity for routine tasks.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS9231955B1Multiparty authorization for controlling resource access
Publication Date: 2016.01.05 EMC IP HLDG CO LLC
  • US9231955B1 patent drawing
  • US9231955B1 patent drawing
  • US9231955B1 patent drawing

AI summary

The subject disclosure is generally directed towards an automated mechanism in a computer network or system that controls resource access to any resource designated as needing multiparty authorization. In one aspect, a resource that needs multiparty authorization before access is allowed is identified, along with policy that specifies an authorizer (or multiple authorizers) for the resource. An access control list may contain metadata that indicates the need for multiparty authorization. Authorization may be provided via a token, which may be cached for future use.