Resource Entitlement Server for Anonymous Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems for managing entitlements and authentication in computer networking environments fail to provide secure, anonymous access to secure web sites and services, particularly in scenarios where users do not want to disclose their identity, lack the necessary credentials, or require temporary access without incurring subscription costs.

Innovation Solution

A system and method that utilize a Resource Entitlement Computer Server (RECS) to manage and verify user attributes for access to resources, allowing users to access resources anonymously by using dynamic events and access criteria, and providing temporary credentials to ensure privacy and convenience.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional authentication systems are used to verify user identity for resource access, then security and access control are improved, but user privacy and anonymity are compromised

Engineering Contradiction:
Improveaccess control securityVSAvoiduser identity privacy
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent introduces an intermediary authentication mechanism that verifies user credentials without exposing identity information. The system uses token-based authentication where the intermediary service validates credentials and grants access rights without revealing the actual user identity to the resource being accessed, thus maintaining both security and privacy.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The authentication system is segmented into separate functional components: credential verification, identity validation, and access authorization. This segmentation allows the system to verify user credentials and grant appropriate access rights without transmitting or storing sensitive identity information, thereby maintaining security while protecting user privacy.

Inventive Principle:
Principle #1Segmentation

2Reliability

If subscription-based access models are implemented for secure resources, then resource provider revenue and service quality are improved, but user convenience and accessibility are reduced

Engineering Contradiction:
Improveservice qualityVSAvoidaccess convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system performs preliminary authentication and credential verification before the user actually needs to access the resource. User credentials are validated in advance, and access rights are pre-configured based on subscription levels, eliminating the need for repeated subscription management during resource access and improving convenience while maintaining service quality.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The authentication system enables self-service capabilities where users can manage their own credentials and access rights without requiring manual intervention from service providers. The system automatically verifies credentials and grants access based on pre-configured subscription levels, improving both user convenience and service reliability.

Inventive Principle:
Principle #25Self-service

3Ease of operation

If permanent credentials are issued for resource access, then user convenience is improved, but security risks and credential management complexity increase

Engineering Contradiction:
Improveaccess convenienceVSAvoidcredential security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements dynamic credentials that are temporary and context-specific rather than permanent. Credentials are generated for specific time periods, resource types, or access scenarios, and automatically expire or become invalid after use. This dynamic approach maintains user convenience while significantly reducing security risks associated with permanent credential exposure.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes the parameters of credentials from static and permanent to dynamic and temporary. Credentials include time-based validity periods, resource-specific scopes, and usage conditions that automatically alter their effectiveness. This parameter transformation allows convenient access while reducing security risks through automatic credential expiration and scope limitation.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS7549054B2System, method, service method, and program product for managing entitlement with identity and privacy applications for electronic commerce
Publication Date: 2009.06.16 GOOGLE LLC
  • US7549054B2 patent drawing
  • US7549054B2 patent drawing
  • US7549054B2 patent drawing

AI summary

A system, method, service method, and program product for defining and/or managing entitlements and/or authentication entitlements to resources in a computer networking environment is disclosed. Upon receiving one or more dynamic events, the invention verifies one or more users (a selected user) has (entitlement) attributes that satisfy one or more access criteria to access one or more resources. The invention then permits and/or provides access to one or more resources for the selected user over one or more networks without revealing the identity of the selected user to the resource provider.