Plug-in Privilege Control via Unique PIN Mapping

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional plug-in privilege control methods lack precision, often resulting in unwanted security compromises due to simple two-level schemes for services and plug-ins, leading to potential security leaks as plug-ins may access services they shouldn't.

Innovation Solution

A system and method for plug-in privilege control that assigns a unique Plugin Identification Number (PIN) to each plug-in, stores mapping of plug-ins to accessible services, and implements conditional accessibility parameters, allowing granular control over service access based on plug-in identity and usage patterns.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a two-level service and plug-in scheme is used for privilege control, then security management is simplified and ease of operation is improved, but manufacturing precision of privilege control deteriorates leading to security leaks

Engineering Contradiction:
Improveease of privilege controlVSAvoidprecision of privilege control
Core Design Contradiction:
Ease of operationVSManufacturing precision

Solution Approach 1:

The patent segments the two-level privilege scheme into multiple granular service levels (e.g., level 1, level 2, level 3) and assigns specific services to each level. This allows precise control over which services each plug-in can access, resolving the contradiction by maintaining simplicity through structured segmentation while achieving fine-grained precision control.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies local quality by assigning different service level permissions to different services based on their sensitivity and importance. Critical services are restricted to higher levels while less sensitive services are accessible at lower levels, enabling precise privilege control tailored to each service's security requirements without overwhelming complexity.

Inventive Principle:
Principle #3Local quality

2Adaptability or versatility

If all services at one level are opened to a plug-in, then the plug-in can function fully at that level, but security leakage risk increases as unwanted services may be accessed

Engineering Contradiction:
Improvefunctionality of plug-inVSAvoidsecurity leakage risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments services into distinct levels with clearly defined access permissions. Each plug-in is assigned to a specific service level and can only access services at that level or lower, preventing unauthorized access to higher-level services while maintaining full functionality within the permitted scope.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements preliminary action by pre-defining service levels and assigning services to appropriate levels before plug-in deployment. This upfront structuring ensures that plug-ins can only access authorized services from the beginning, eliminating the need for runtime security checks and preventing security leaks while maintaining versatility.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If sensitive interfaces are closed to protect security, then security is improved, but adaptability of the host application deteriorates

Engineering Contradiction:
Improvesecurity of host applicationVSAvoidopenness of host application
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent applies dynamics by making service accessibility dynamic based on plug-in service level assignments. Services are not statically closed or open but are dynamically accessible based on the plug-in's assigned level and the service's defined permissions, allowing the system to maintain security while adapting to different plug-in requirements.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent uses parameter changes by varying the service level parameter to control access. By changing the service level assignment parameter, the system can precisely control which services are accessible to each plug-in, maintaining security through parameter-based restrictions while preserving adaptability through flexible parameter configuration.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentEP2457152B1Method and system of plug-in privilege control
Publication Date: 2018.09.19 ALIBABA GROUP HOLDING LTD
  • EP2457152B1 patent drawingFigure 1
  • EP2457152B1 patent drawingFigure 2
  • EP2457152B1 patent drawingFigure 3

AI summary

A plug-in privilege control includes authorizing a plug-in, including assigning a plug-in identification number (PIN) to the plug-in wherein the PIN is used to identify an identification (ID) of the corresponding plug-in; notifying the plug-in about the PIN; storing information about the plug-in and a plug-in accessible service to a mapping of services; receiving a request for a service from the plug-in, wherein the request includes the PIN; retrieving the ID of the plug-in according to the PIN; and determining whether to allow the plug-in to access the service that it requested.