Offline Authorization via Agent and Cryptographic Certificates

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional authorization methods require uninterrupted connections between clients, providers, and resource owners for transactions, making offline scenarios impossible or unreliable.

Innovation Solution

A method involving wireless communication through an agent to transmit resource requests and authorization responses between clients, providers, and resource owners, allowing for resource release or blocking even in offline or temporarily disconnected scenarios, using cryptographic techniques for secure communication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional authorization methods are used with continuous connection requirements, then security and reliability of authorization are improved, but system availability and ease of operation deteriorate due to mandatory uninterrupted connections

Engineering Contradiction:
Improveauthorization reliabilityVSAvoidoperation availability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system performs preliminary actions by generating and storing authorization certificates and cryptographic keys before disconnection occurs. The resource owner and provider establish trust relationships and exchange cryptographic materials in advance, allowing the client to operate offline with pre-configured authorization credentials.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces cryptographic certificates and digital signatures as intermediaries that mediate authorization between parties without requiring direct real-time connection. The certificate acts as a trusted intermediary that validates authorization requests even when the original parties are disconnected.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If uninterrupted connections are maintained between all parties, then real-time authorization control is improved, but system complexity and loss of time increase due to connection management requirements

Engineering Contradiction:
Improvereal-time authorization controlVSAvoidconnection management time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

Authorization credentials and cryptographic certificates are established in advance before disconnection. The system performs all necessary authentication setup, key exchange, and certificate validation in preliminary steps, eliminating the need for real-time connection management during offline operations.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent creates cryptographic copies (certificates and signed authorization tokens) that replicate the authorization function without requiring the original connection. These digital copies can be stored and presented offline, replacing the need for real-time communication.

Inventive Principle:
Principle #26Copying

3Reliability

If cryptographic techniques are implemented for secure offline communication, then security and fraud prevention are improved, but device complexity increases due to cryptographic protocol requirements

Engineering Contradiction:
Improvesecurity and fraud preventionVSAvoidcryptographic protocol complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent uses standardized cryptographic intermediaries (X.509 certificates, digital signatures, public key infrastructure) that mediate secure communication without requiring custom cryptographic protocols. These well-established intermediaries simplify implementation while maintaining high security standards.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The cryptographic certificate system serves multiple functions simultaneously: authentication, authorization, encryption, and non-repudiation. This multi-functionality reduces overall system complexity by consolidating multiple security mechanisms into a single universal cryptographic framework.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11374921B2Authorization method for the release or blocking of resources and client
Publication Date: 2022.06.28 DEUTSCHE TELEKOM AG
  • US11374921B2 patent drawing
  • US11374921B2 patent drawing
  • US11374921B2 patent drawing

AI summary

An authorization method for releasing or blocking resources includes, in case there is no connection between a provider and a resource owner: wirelessly transmitting a resource request from a client to the provider via an agent; wirelessly transmitting an authorization request from the provider to the client via the agent; wirelessly transmitting the authorization request from the client to the resource owner; wirelessly transmitting a receipt comprising an authorization response from the resource owner to the client; wirelessly transmitting the receipt from the client to the provider; and releasing or blocking a first resource in accordance with the authorization response comprised in the receipt.