Personal Domain Controller for Secure Remote Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Users face challenges when remotely accessing sensitive resources from untrusted terminals, as they must choose between granting full access or restricted access, which may not meet dynamic needs and can lead to insecure operations or incorrect access guesses.
Innovation Solution
A method is implemented using a client device with a local port for communication with untrusted terminals and a network port for secure access to a home network, employing access control points like search, update, transfer, and privacy control points to ensure secure, one-time access to specific resources using credentials and a reference monitor for authorization.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If full access is granted to untrusted terminals, then ease of operation is improved, but security is worsened
Solution Approach 1:
The patent introduces an intermediary access control system that mediates between untrusted terminals and sensitive resources. The system uses credentials and reference monitors to verify authorization requests, allowing legitimate access while blocking unauthorized operations. This intermediary layer resolves the contradiction by enabling ease of operation for authorized users while maintaining security against untrusted terminals.
2Reliability
If restricted access roles are created, then security is improved, but adaptability is worsened
Solution Approach 1:
The patent implements dynamic access control where authorization decisions are made in real-time based on credentials presented by the terminal and resources requested by the user. Rather than static pre-defined roles, the system dynamically evaluates each access request against the user's actual credentials and the specific resource being accessed, resolving the contradiction between security and adaptability.
Solution Approach 2:
The system changes the parameter of access control from fixed role-based permissions to dynamic credential-based authorization. By changing how access rights are determined (from static roles to dynamic credential verification), the system achieves both security through verification and adaptability through flexible resource access based on actual user needs.
3Ease of operation
If pre-defined access policies are used, then ease of operation is improved, but adaptability is worsened
Solution Approach 1:
The patent replaces static pre-defined access policies with dynamic authorization evaluation. The system evaluates access requests in real-time based on the terminal's credentials and the specific resource being accessed, allowing users to access resources they need without preconfiguration while maintaining security through credential verification.
Data Source
AI summary
A method of accessing a data resource identifies the data resource, the data resource accessible through a first device and associated with a resource locator, the first device configured to provide access to the data resource responsive to possession of a whitelisted credential. The method includes receiving a second-device credential from a second device by a personal domain controller, the personal domain controller and the first device within a first trusted relationship and provides, by the personal domain controller, the second-device credential to the first device for whitelisting subject to the first trusted relationship. The method uses, by the second device, the second-device credential to access the data resource responsive to the resource locator.


