Network Access Control via Distributed Key Signing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network services are vulnerable to cybercrimes due to unauthorized access, which compromises private information and resources.

Innovation Solution

A method and system for optimized access control, where an infrastructure device transmits an invitation link to a distributor device, which activates the link, generates a key pair, and signs action requests to validate access to network services.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional access control methods are used for network services, then ease of operation is maintained, but security against cybercrimes is insufficient

Engineering Contradiction:
ImprovesecurityVSAvoidaccess control complexity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system performs preliminary actions by generating cryptographic key pairs and signing action requests before actual network service operations. The infrastructure device signs action requests with private keys before transmission, and the distributor device verifies these signed requests using public keys, establishing security credentials in advance rather than during critical operations.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces cryptographic keys and digital signatures as intermediary elements between the distributor device and infrastructure device. These intermediaries enable secure verification of action requests without requiring direct trust relationships or complex authentication protocols between the communicating parties.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If cryptographic verification is implemented for all action requests, then security is improved, but processing time increases

Engineering Contradiction:
Improveaccess control securityVSAvoidverification time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The cryptographic verification is performed as a preliminary action before the actual network service operation. By signing and verifying action requests in advance, the system ensures security credentials are validated before resource-intensive operations commence, preventing wasted processing time on unauthorized requests.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If distributed access control is implemented, then service availability is improved, but security vulnerability increases

Engineering Contradiction:
Improveservice distribution capabilityVSAvoidsecurity risk
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent uses cryptographic keys and digital signatures as intermediary verification mechanisms that enable distributed access control while maintaining security. Each distributor device can independently verify signed action requests using public keys, allowing decentralized service distribution without centralizing security validation, thus reducing security risks associated with distributed architectures.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12273465B2Optimized access control for network services
Publication Date: 2025.04.08 UAB 360 IT
  • US12273465B2 patent drawing
  • US12273465B2 patent drawing
  • US12273465B2 patent drawing

AI summary

A method including transmitting, by an infrastructure device to a distributor device, an invitation link to enable the distributor device to distribute to a user device network services provided by the infrastructure device; transmitting, by the infrastructure device to the distributor device based on the distributor device activating the invitation link, seed information to be utilized by the distributor device to determine a distributor key pair including a distributor public key and a distributor private key; receiving, by the infrastructure device from the distributor device, an action request related to an action to be performed regarding the network services, a portion of the action request being signed based on utilizing the distributor private key; and enabling, by the infrastructure device, performance of the action regarding the network services based on validating the action request by utilizing the distributor public key is disclosed.