Automated Privilege Delegation via Cryptographic Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for granting privileges to lower-privileged entities on devices require physical access and administrative intervention, resulting in increased costs due to travel, transportation, and working hours.

Innovation Solution

Automating the introduction of privileges by pre-providing devices with necessary privileges, allowing a higher-privileged entity to remotely or pre-install a higher-privileged instance that can set up lower privileges using cryptographic verification, eliminating the need for administrative intervention.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If an administrator manually configures privileges on a device by physical access, then privilege delegation can be performed with full control and verification, but travel costs, time costs, and administrative effort increase significantly

Engineering Contradiction:
Improveprivilege delegation controlVSAvoidadministrator travel time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies preliminary action by pre-configuring trust relationships and cryptographic verification mechanisms on the device before administrative intervention is needed. The device is pre-provisioned with ability to autonomously verify administrator identity and execute privilege delegation commands remotely, eliminating the need for physical presence while maintaining security control.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If an administrator manually configures privileges on a device by physical access, then privilege delegation can be performed with full control and verification, but transportation costs and device downtime increase

Engineering Contradiction:
Improveprivilege delegation controlVSAvoiddevice availability
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements self-service by enabling the device to autonomously handle privilege delegation operations. The device can independently verify administrator credentials through cryptographic methods and execute privilege configuration commands without requiring physical administrator presence, thereby eliminating device transport needs and minimizing downtime while maintaining secure control.

Inventive Principle:
Principle #25Self-service

3Productivity

If automated privilege delegation is implemented without physical access, then time costs and transportation costs are reduced, but security verification and authorization control become more challenging

Engineering Contradiction:
Improveadministrative efficiencyVSAvoidauthorization verification
Core Design Contradiction:
ProductivityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent replaces mechanical physical verification methods with cryptographic electronic verification systems. Instead of requiring physical presence for identity verification and authorization, the system uses digital signatures, public key infrastructure, and secure communication protocols to authenticate administrators and verify privilege delegation commands remotely, maintaining security while enabling automated efficient operations.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

Reduces the effort and costs associated with setting up privileges by enabling automated privilege delegation without requiring physical presence or administrative intervention, allowing authorized entities to access necessary functions.

Implementation Method 1

Whether an instance possesses the necessary privilege could be verified, for example, by means of a cryptographic signature with which the instance is secured.

Methodology Applied
Scientific EffectCryptographic signature verification:

Data Source

PatentEP2038805B1Method for delegating privileges to a lower level privilege instance by a higher level privilege instance
Publication Date: 2019.08.28 T MOBILE INTERNATSIONAL AG
  • EP2038805B1 patent drawingFigure 1

AI summary

The invention relates to a method for a higher level privilege instance to delegate privileges to a lower level privilege instance, through which the granting of privileges, P1, to a lower level privilege instance in a data processing device is automatically carried out. The device is provided with functions for setting up required privileges before distribution to a user or by long distance data transmission and, hence, privileges, P1, can be provided to the lower level privilege instance with the help of a higher level privilege instance which has special privileges, P2, which authorize the assignment of privileges.