Peer-to-Peer Resource Access Delegation via Delegate Attributes
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional methods for allowing additional users to access resources associated with an account are complex and inefficient for individual users, lacking user-friendly and cost-effective solutions for delegating access without the need for administrators or access-control roles/policies.
Innovation Solution
A mechanism for establishing a negotiated resource access arrangement between owner and borrower accounts, enabling the owner to grant specific access rights to a second user through a delegate, which includes attributes like schedule, target, condition, and scope, allowing controlled access to resources without requiring an administrator or complex access control systems.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional access control systems with administrators and role-based access control are used, then access permissions can be controlled, but the system complexity increases significantly for individual users
Solution Approach 1:
The patent extracts the administrator function from the system by enabling direct peer-to-peer access delegation between users. The owner account directly grants access to borrower accounts without requiring an intermediate administrator to manage roles and policies, thus maintaining access control reliability while eliminating system complexity.
Solution Approach 2:
The system implements self-service access control where the owner account autonomously manages access delegation to borrower accounts. The owner can directly grant, modify, and revoke access permissions without external administrative intervention, simplifying the system while maintaining control reliability.
2Ease of operation
If full access rights are granted to a second user, then the user can access the resource freely, but the owner loses control over access permissions
Solution Approach 1:
The patent segments access permissions into specific attributes including schedule, target, condition, and scope. This allows the owner to grant partial access rights to borrower accounts rather than full access, enabling fine-grained control over when, where, and how the borrower can access the resource while maintaining ease of operation through structured permission definitions.
Solution Approach 2:
The system applies local quality by allowing different access permissions for different resources or different time periods. The owner can specify that the borrower has full access to certain resources during specific schedules but limited or no access to others, providing customized access control that balances ease of operation with maintained reliability.
3Reliability
If complex access control policies are implemented, then access can be restricted according to specific roles, but the process becomes impractical for individual consumers
Solution Approach 1:
The patent creates a universal access control mechanism that serves both individual consumers and organizational users through the same delegate relationship model. The four attributes (schedule, target, condition, scope) provide multi-functional control capabilities that work for simple resource sharing as well as for complex organizational access requirements, making the system universally applicable without requiring different approaches for different user types.
Data Source
AI summary
An improved method and system of enabling the owner of an account associated with a resource to allow a second user to gain access to the resource or a particular aspect of the resource is disclosed. Solutions and implementations disclosed provide an easily manageable mechanism for allowing access to a resource, without the need for a complex administrator-based access control system. Instead, a negotiated account to account resource access arrangement is established between the first user's account and the second user's account to share some or all of the actions available to the first user for the resource.


