Non-Bidirectional Security Voucher for Remote Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing electronic security systems for non-bidirectional communication protocols lack secure measures for controlled access and dynamic management of user rights, as they cannot establish bidirectional connections necessary for real-time interactions and secure data exchange.
Innovation Solution
A method and system that use non-bidirectional communication protocols to securely distribute encrypted electronic information by retrieving identification data, sending a voucher with an encryption key and policy constraints, and decrypting the information at the user device, with features like unique encryption keys and validity periods to manage access rights dynamically.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If bidirectional communication protocols are used for secure access control, then real-time interaction and dynamic rights management are improved, but compatibility with non-bidirectional messaging networks is worsened
Solution Approach 1:
Instead of requiring bidirectional communication for security, the patent inverts the approach by using unidirectional messaging with embedded security credentials (vouchers) that contain encryption keys and policy constraints. The security model is reversed from continuous verification to initial verification with offline credentials.
Solution Approach 2:
The patent introduces vouchers as intermediary objects that mediate between the policy server and client application. These vouchers encapsulate security credentials and policy constraints, allowing secure communication over non-bidirectional networks by acting as self-contained security tokens.
2Productivity
If connection-based bidirectional protocols are used, then real-time policy enforcement is improved, but functionality in switched messaging networks is worsened
Solution Approach 1:
The patent applies preliminary action by pre-packaging policy constraints and encryption keys into vouchers before transmission. This allows policy enforcement to occur offline without requiring real-time connection to the policy server, enabling functionality in asynchronous messaging networks.
Solution Approach 2:
The patent creates copies of security credentials and policy information in the form of vouchers that can be transmitted independently through messaging networks. These voucher copies enable client applications to enforce policies locally without continuous connection to the original policy server.
3Reliability
If encryption keys are distributed dynamically over bidirectional networks, then access control security is improved, but implementation in non-bidirectional environments is worsened
Solution Approach 1:
The patent merges encryption keys, policy constraints, and validity information into a single voucher object. This consolidation simplifies implementation in non-bidirectional networks by eliminating the need for separate key distribution and policy management channels.
Solution Approach 2:
The patent changes the state of encryption keys from being dynamically exchanged over bidirectional connections to being statically embedded in vouchers with fixed validity periods and policy constraints. This parameter change enables operation in asynchronous messaging environments.
Data Source
AI summary
A system and method of controlling distribution of electronic information to a device through a non-bidirectional protocol is disclosed. At a user device, a segment of encrypted electronic information is retrieved. Identification data is sent from the user device using the non-bidirectional communications protocol, where the identification information includes at least one of information associated with a user, information associated with the user device, or information associated with the segment of encrypted electronic information. A copy of an encryption key for the segment is retrieved. A voucher is forwarded to the user device using the non-bidirectional communications protocol, the voucher including at least the encryption key associated with the segment. At the user device, the segment is decrypted using the encryption key for the segment.


