Remote Access Broker With Double Approval Across Tenants

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Managing user access across different organizations in partnerships is cumbersome, often requiring manual intervention or inadequate security and control.

Innovation Solution

A remote access broker that facilitates cross-tenant vendor identity management, allowing 'double approval' for user access, sharing user lists or groups, and managing access permissions across multiple organizations without onboarding or new email registrations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual intervention and configuration are used for access management, then security and control are improved, but operation complexity and time consumption increase

Engineering Contradiction:
Improvesecurity and controlVSAvoidoperation complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

An access broker is introduced as an intermediary system between tenants and users. The broker automatically manages access permissions by receiving access requests, verifying user identities, checking tenant policies, and granting or denying access without requiring manual intervention from tenant administrators, thus maintaining security while reducing operational complexity

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system enables self-service access management where users can independently request access to tenants through the broker, and the broker automatically processes these requests by verifying credentials and applying security policies, eliminating the need for manual user provisioning and access configuration by tenant administrators

Inventive Principle:
Principle #25Self-service

2Reliability

If manual configuration is used for cross-organization access, then security control is improved, but time consumption and productivity decrease

Engineering Contradiction:
Improvesecurity controlVSAvoidtime consumption
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

Tenant security policies, user credentials, and access permissions are pre-configured in the system before access requests occur. The broker uses these pre-established policies to automatically evaluate and process access requests in real-time, eliminating the need for manual security configuration during each access event and significantly reducing time consumption

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The access broker serves as an automated intermediary that rapidly processes access requests by automatically verifying user identities against pre-configured tenant policies and making access decisions without human intervention, thus maintaining strict security control while dramatically reducing the time required for cross-organization access management

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If automated access management is implemented, then productivity is improved, but security control and reliability worsen

Engineering Contradiction:
Improveaccess management efficiencyVSAvoidsecurity control
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The broker implements feedback mechanisms where access decisions are logged, monitored, and can be audited. The system continuously verifies user credentials against tenant policies and provides feedback on access request status, allowing for automatic enforcement of security rules while maintaining high productivity through streamlined automated processes

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

While maintaining automated high-speed processing, the system allows tenant administrators to self-configure security policies and access rules according to their specific security requirements. This enables automated productivity improvement while preserving security control, as each tenant can tailor the automated system to their security needs without manual intervention in each access event

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS20250350604A1Remote access broker for secure equipment access
Publication Date: 2025.11.13 CISCO TECHNOLOGY INC
  • US20250350604A1 patent drawing
  • US20250350604A1 patent drawing
  • US20250350604A1 patent drawing

AI summary

In one embodiment, a method includes determining, by an access broker, a first group of users of a first tenant within a computer network and exposing, by the access broker, the first group of users to a second tenant within the computer network. The method may further include receiving, by the access broker, a selection of particular users from the first group of users for which the second tenant has granted remote access to one or more networked assets of the second tenant and managing, by the access broker, access of the particular users of the first tenant to the one or more networked assets of second tenant based on a group configuration for the first group of users by the first tenant and the selection of the particular users by the second tenant.