Non-Bidirectional Security Voucher for Remote Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing electronic security systems for non-bidirectional communication protocols lack secure measures for controlled access and dynamic management of user rights, as they cannot establish bidirectional connections necessary for real-time interactions and secure data exchange.

Innovation Solution

A method and system that use non-bidirectional communication protocols to securely distribute encrypted electronic information by retrieving identification data, sending a voucher with an encryption key and policy constraints, and decrypting the information at the user device, with features like unique encryption keys and validity periods to manage access rights dynamically.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If bidirectional communication protocols are used for secure access control, then real-time interaction and dynamic rights management are improved, but compatibility with non-bidirectional messaging networks is worsened

Engineering Contradiction:
Improvesecure access controlVSAvoidnetwork compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

Instead of requiring bidirectional communication for security, the patent inverts the approach by using unidirectional messaging with embedded security credentials (vouchers) that contain encryption keys and policy constraints. The security model is reversed from continuous verification to initial verification with offline credentials.

Inventive Principle:
Principle #13The other way round (Inversion)

Solution Approach 2:

The patent introduces vouchers as intermediary objects that mediate between the policy server and client application. These vouchers encapsulate security credentials and policy constraints, allowing secure communication over non-bidirectional networks by acting as self-contained security tokens.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If connection-based bidirectional protocols are used, then real-time policy enforcement is improved, but functionality in switched messaging networks is worsened

Engineering Contradiction:
Improvereal-time policy enforcementVSAvoidmessaging network functionality
Core Design Contradiction:
ProductivityVSAdaptability or versatility

Solution Approach 1:

The patent applies preliminary action by pre-packaging policy constraints and encryption keys into vouchers before transmission. This allows policy enforcement to occur offline without requiring real-time connection to the policy server, enabling functionality in asynchronous messaging networks.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent creates copies of security credentials and policy information in the form of vouchers that can be transmitted independently through messaging networks. These voucher copies enable client applications to enforce policies locally without continuous connection to the original policy server.

Inventive Principle:
Principle #26Copying

3Reliability

If encryption keys are distributed dynamically over bidirectional networks, then access control security is improved, but implementation in non-bidirectional environments is worsened

Engineering Contradiction:
Improveaccess control securityVSAvoidimplementation complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges encryption keys, policy constraints, and validity information into a single voucher object. This consolidation simplifies implementation in non-bidirectional networks by eliminating the need for separate key distribution and policy management channels.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent changes the state of encryption keys from being dynamically exchanged over bidirectional connections to being statically embedded in vouchers with fixed validity periods and policy constraints. This parameter change enables operation in asynchronous messaging environments.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS7458102B2Information security architecture for remote access control using non-bidirectional protocols
Publication Date: 2008.11.25 DELL EMC
  • US7458102B2 patent drawing
  • US7458102B2 patent drawing
  • US7458102B2 patent drawing

AI summary

A system and method of controlling distribution of electronic information to a device through a non-bidirectional protocol is disclosed. At a user device, a segment of encrypted electronic information is retrieved. Identification data is sent from the user device using the non-bidirectional communications protocol, where the identification information includes at least one of information associated with a user, information associated with the user device, or information associated with the segment of encrypted electronic information. A copy of an encryption key for the segment is retrieved. A voucher is forwarded to the user device using the non-bidirectional communications protocol, the voucher including at least the encryption key associated with the segment. At the user device, the segment is decrypted using the encryption key for the segment.