Network Access Control via Signed Manager Requests

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network services are vulnerable to cybercrimes due to unauthorized access, which can lead to data theft, alteration, or destruction, compromising private information and sensitive data.

Innovation Solution

A method and system that involve an infrastructure device transmitting an invitation link to a manager device to manage network services, with the manager device receiving seed information to determine authorization, and then transmitting a manager request signed with authorization information during an active communication session.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional access control methods are used, then device complexity is reduced, but security reliability deteriorates due to vulnerability to cybercrimes and unauthorized access

Engineering Contradiction:
Improveaccess control securityVSAvoidaccess control system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The access control system is segmented into distinct functional components: invitation link generation module, seed information transmission module, authorization information determination module, manager request signing module, and verification module. Each component handles a specific aspect of the access control process, making the system more manageable while enhancing security through specialized functionality.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary actions by generating and transmitting invitation links before actual access is needed. The infrastructure device sends invitation links to manager devices in advance, allowing managers to prepare authorization information before actual network service management operations occur. This preliminary setup establishes secure authorization frameworks before potential cyber threats can exploit the system.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If invitation link and seed information mechanism is implemented, then authorization reliability is improved, but communication time and data transmission increase

Engineering Contradiction:
Improveauthorization reliabilityVSAvoidcommunication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system extracts critical authorization data into separate, dedicated components: invitation links are extracted as distinct transmission elements, and seed information is extracted as a separate authorization foundation. This extraction allows these elements to be transmitted and processed independently, optimizing the authorization flow while maintaining security. The manager request signing process extracts authentication requirements into a dedicated signing mechanism that verifies authorization without requiring re-transmission of all previous data.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If manager request signing with authorization information is implemented, then access control security is improved, but processing complexity increases

Engineering Contradiction:
Improveaccess control securityVSAvoidrequest processing complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system introduces an intermediary signing mechanism that mediates between the manager device and the infrastructure device. The manager request signing module acts as an intermediary that takes authorization information and transforms it into signed requests, while the verification module serves as an intermediary that validates these signed requests. This intermediary approach simplifies the overall processing by providing standardized interfaces for authorization and verification.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If communication session verification is added, then unauthorized access prevention is improved, but system response time increases

Engineering Contradiction:
Improveunauthorized access preventionVSAvoidsystem response time
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

The system implements periodic verification of communication session validity during the authorization process. Rather than continuous verification, the system performs verification at key periodic points: when the invitation link is transmitted, when seed information is received, when manager requests are signed, and when authorization decisions are made. This periodic verification approach maintains security while reducing the cumulative time overhead compared to continuous verification.

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS20250080432A1Access control for network services
Publication Date: 2025.03.06 UAB 360 IT
  • US20250080432A1 patent drawing
  • US20250080432A1 patent drawing
  • US20250080432A1 patent drawing

AI summary

A method including receiving, by a manager device from an infrastructure device, seed information including unique information associated with manager device to enable the manager device to determine authorization information; determining, by the manager device, the authorization information based at least in part on utilizing the unique information; transmitting, by the manager device to the infrastructure device, a manager request related to an action to be performed regarding the network services, the manager request being signed based at least in part on utilizing a portion of the authorization information; and performing, by the manager device based at least in part on authorization of the manager request by the infrastructure device, the action regarding the network services is disclosed. Various other aspects are contemplated.