Router Social Network Authentication ACL Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing social networking services face challenges in securely and conveniently sharing access to resources and objects among trusted groups without exposing critical login data, and in managing access control lists (ACLs) in a centralized and user-friendly manner.

Innovation Solution

A computer-implemented method and apparatus that utilizes a social networking service as a central authentication source, where a router or client device displays a login view, transmits login data, and receives an authorization code to access a destination or object, maintaining ACLs centrally and limiting exposure of login data, while allowing secure and controlled access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If login data is transmitted to accessible objects for authentication, then access control is enabled, but security is worsened due to exposure of critical login data

Engineering Contradiction:
Improveaccess controlVSAvoidlogin data exposure
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a social networking service as an intermediary authentication server that mediates between the client device and the accessible object. The client device transmits login data only to this intermediary service, which then handles authentication and returns authorization codes. This prevents direct exposure of login data to accessible objects while maintaining access control functionality.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If ACLs are maintained locally at each accessible object, then access control is decentralized, but device complexity and maintenance difficulty increase

Engineering Contradiction:
Improvedecentralized access controlVSAvoidACL management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent merges the ACL management functionality from multiple distributed accessible objects into a single centralized social networking service. Instead of each accessible object maintaining its own ACL locally, all access control lists are consolidated in the intermediary authentication service, simplifying device complexity while maintaining decentralized access control capabilities through centralized management.

Inventive Principle:
Principle #5Merging (Combining)

3Ease of operation

If users share credentials directly with accessible objects, then access sharing is simple, but security is worsened due to credential exposure

Engineering Contradiction:
Improveaccess sharing simplicityVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent uses the social networking service as an intermediary that enables users to share access to accessible objects without exposing their credentials. The intermediary handles the authentication process and manages authorization codes, allowing users to grant access to trusted contacts while the service provider maintains security by never exposing actual login credentials.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS9141778B2Controlling access to an accessible object with an online access control list
Publication Date: 2015.09.22 GOOGLE LLC
  • US9141778B2 patent drawing
  • US9141778B2 patent drawing
  • US9141778B2 patent drawing

AI summary

Software on a router receives configuration data that specifies a social networking service as a source for authentication according to an authentication protocol. Subsequently, the router software receives packet data from a client device for a destination other than the social networking service. The router software causes software on the client device to display a login view for the social networking service. The router software transmits the login data entered in the login view to the social networking service. And the router software receives an authorization code following a successful login by a user identified on an access control list (ACL). Then the router software transmits the packet data to the destination.