Remote Dual-Party Authorization for Sensitive Operations
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional data protection systems require a security officer to be physically present to authorize sensitive operations, leading to issues such as compromised credentials, unavailability, and limited automation capabilities, as well as restricted oversight to both control and data paths.
Innovation Solution
A framework enabling remote authorization by a security officer, allowing pre-approval of requests, automating operations, and enabling dual-party authorization to enhance oversight and control over sensitive operations, while maintaining customer control over third-party vendors.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a security officer is required to be physically present to authorize sensitive operations, then security control is maintained, but operational efficiency and availability are reduced
Solution Approach 1:
The patent replaces the mechanical requirement of physical presence with an electronic authorization system. The security officer's authorization is transferred from a physical presence requirement to an electronic token or credential that can be remotely presented, substituting the mechanical interaction with an electronic one. This allows the same security control function to be achieved without the physical presence constraint, thereby improving operational efficiency while maintaining security reliability.
2Reliability
If a security officer is required to be physically present for authorization, then direct oversight is ensured, but credential compromise risk increases due to potential sharing or exposure
Solution Approach 1:
The patent introduces an intermediary authorization token or electronic credential that mediates between the security officer and the sensitive operation. Instead of the security officer's physical presence or direct credential exposure being required, the system uses this intermediary token to convey authorization. This intermediary layer protects the security officer's credentials from compromise while ensuring oversight is maintained, as the token can be configured with specific authorization scopes and validity periods.
3Reliability
If physical presence is required for security officer authorization, then real-time approval is obtained, but automation capability is limited
Solution Approach 1:
The patent makes the authorization system dynamic by allowing the security officer to grant authorization tokens with configurable parameters such as validity duration, operation scope, and conditional requirements. This dynamic authorization approach enables the system to adapt to different operational contexts automatically. For routine operations, pre-configured tokens enable automated execution, while more complex scenarios can require interactive renewal or modification of authorization, thus balancing real-time control with automation capability.
4Reliability
If a traditional physical authorization system is used, then security control is maintained, but user experience and remote access capability are reduced
Solution Approach 1:
The patent creates a universal authorization system where the same electronic token or credential mechanism can be used across multiple contexts and locations. The security officer can issue authorization that works for the user regardless of physical location, and the same system supports both automated and interactive authorization scenarios. This multi-functional approach improves user experience by enabling remote access while maintaining security control through a unified system that adapts to different operational requirements.
Data Source
AI summary
A method for managing an operation includes: receiving a request from a data protection module with respect to assigning a security officer role (SOR) to a person; in response to the request and at a first point-in-time, initiating assignment of the SOR to the person; receiving, at a second point-in-time, a notification from the data protection module indicating that the SOR is assigned to the person; in response to the notification, sending a second request to the data protection module to execute the operation; after the sending the second request: making a first determination that the second request has not been approved; waiting, based on the first determination, until the second request is approved by the person or a second person assigned the SOR; making a second determination that the second request is approved by the second person; and continuing, based on the second determination, execution of the operation.


