Resource Upload Access Control via Proxy

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for sharing resources between different third-party services require either granting blanket access or manual download and upload, which pose security risks, lack control over access, and are cumbersome, especially on low-bandwidth connections.

Innovation Solution

A method and system that allow a client device to connect to remote storage, initiate and manage resource uploads to a remote service, enabling selective access control, secure encrypted transfers, and asynchronous retrieval, without requiring permanent access to the resource repository.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If blanket access is granted to third-party services, then resource sharing is enabled, but security risks increase and user control is lost

Engineering Contradiction:
Improveresource sharing capabilityVSAvoidsecurity risk
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments access rights by allowing users to selectively authorize specific resources (files, folders) to specific third-party services rather than granting blanket access to entire repositories. This is achieved through granular permission settings where users can control which resources are shared and under what conditions, thereby maintaining security while enabling resource sharing.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system implements local quality by allowing different access levels for different resources within the same repository. Users can grant read-only access to public photos while restricting access to private documents, creating localized permission structures that balance sharing needs with security requirements.

Inventive Principle:
Principle #3Local quality

2Ease of operation

If permanent access is granted to third-party services, then resource sharing is simplified, but user control over resource availability is reduced

Engineering Contradiction:
Improveaccess control simplicityVSAvoiduser control over access
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic access control where permissions can be modified, revoked, or updated at any time. Users can change access rights from permanent to time-limited or from broad to specific, allowing the system to adapt to changing user needs while maintaining ease of operation through a unified permission management interface.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system allows users to change access parameters such as time limits, usage conditions, and permission scopes. Users can set expiration dates for access, limit resources to specific file types or folders, and adjust permission levels, thereby maintaining control while simplifying the sharing process.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If manual download and upload is performed, then security control is maintained, but the process becomes cumbersome and slow

Engineering Contradiction:
Improvesecurity controlVSAvoidtransfer speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent introduces an intermediary system that automatically handles resource transfer between third-party services. Instead of requiring users to manually download and upload files, the system uses authorized service-to-service communication channels to transfer resources directly, maintaining security through controlled intermediaries while dramatically improving transfer efficiency.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary authorization actions where users pre-configure permission settings and authentication credentials before needing to transfer resources. This preliminary setup enables automatic, secure transfers without requiring manual intervention at the time of resource sharing, thereby maintaining security control while eliminating the cumbersome manual process.

Inventive Principle:
Principle #10Preliminary action

4Ease of operation

If manual file transfer is initiated on mobile devices, then resource sharing is possible, but system resources are consumed and connection is locked

Engineering Contradiction:
Improveresource sharing capabilityVSAvoidsystem resource consumption
Core Design Contradiction:
Ease of operationVSUse of energy by moving object

Solution Approach 1:

The patent implements self-service functionality where the system automatically manages resource transfer without requiring continuous user intervention or locking the device connection. The system handles authentication, permission verification, and file transfer autonomously using pre-configured credentials and authorization tokens, thereby reducing system resource consumption and maintaining ease of operation on mobile devices.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10044828B2Resource upload
Publication Date: 2018.08.07 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US10044828B2 patent drawing
  • US10044828B2 patent drawing
  • US10044828B2 patent drawing

AI summary

A method, system and program for uploading a resource from remote storage to a remote service. The method comprises the steps of connecting to the remote service, initiating an upload of the resource to the remote service, selecting the remote storage as a source of the resource, acquiring the resource from the remote storage, and uploading the resource to the remote service. In one embodiment, at least part of the method is executed by a proxy server and the step of acquiring the resource from the remote storage comprises downloading the resource to the proxy server. In another embodiment, the remote service communicates directly with the remote storage. In this further embodiment, a client device acquires authentication data for the resource from the remote storage and the step of acquiring the resource from the remote storage includes providing the authentication data to the remote storage.