Scoped Federations for Secure Data Sharing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing mechanisms for sharing data/services between organizations are either inflexible due to centralized management, making them unsuitable for dynamic interactions, or insecure as they lack centralized control, leading to difficulties in managing and controlling the flow of information.

Innovation Solution

A scoped federation system is introduced, where two or more organizations establish trust and create a federation with unique identifiers and rules, allowing secure and flexible data/service sharing by using Security Token Services (STS) to manage access and enforce rules through unique universal IDs (UUIDs) and security tokens.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If centralized management mechanisms (vendor accounts, extranets, cross-certification) are used for data/service sharing, then security and control are improved, but flexibility and ease of operation deteriorate due to IT department management overhead

Engineering Contradiction:
Improvesecurity and controlVSAvoidflexibility
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent segments the federation management into multiple independent components: federation identifiers (UUIDs) for different collaboration contexts, scope rules for accessing specific resources, and security tokens for authentication. This segmentation allows employees to establish multiple scoped federations without centralized IT intervention for each interaction, improving flexibility while maintaining security through structured rule-based access control.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system dynamically creates and manages scoped federations based on specific collaboration needs rather than using static centralized configurations. Employees can establish federations on-demand with unique identifiers and context-specific scope rules, allowing the system to adapt to varying collaboration requirements while maintaining security through enforced access rules.

Inventive Principle:
Principle #15Dynamics

2Ease of operation

If decentralized mechanisms (email, peer to peer sharing, third party services) are used for data/service sharing, then flexibility and ease of operation are improved, but security and centralized control deteriorate

Engineering Contradiction:
ImproveflexibilityVSAvoidsecurity and centralized control
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces an intermediary layer (the scoped federation system with UUIDs and scope rules) between employees and the resources they access. This intermediary enforces security policies and maintains visibility for IT departments while allowing employees to initiate collaborations flexibly. The federation identifier and scope rules act as mediators that enable decentralized initiation with centralized oversight.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system provides feedback mechanisms where scope rules and federation identifiers track and report access patterns to centralized management systems. This allows IT departments to maintain visibility and control over data flow while employees enjoy flexible access, as the feedback loop enables monitoring and policy enforcement without micromanaging individual interactions.

Inventive Principle:
Principle #23Feedback

3Ease of operation

If broad cross-certification is used between organizations, then ease of operation is improved, but security deteriorates due to inability to limit information exposure

Engineering Contradiction:
Improveease of collaborationVSAvoidinformation leakage
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent applies local quality by creating scope rules that are specific to each federation and resource context. Instead of uniform broad access permissions, each scoped federation has localized access rules that define exactly which resources can be accessed and under what conditions. This allows employees to collaborate easily within defined boundaries while preventing information leakage through context-specific access control.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system implements partial action by granting access only to the specific resources and scope defined in each federation's rules, rather than providing complete or excessive access permissions. Employees receive just enough access rights for their specific collaboration needs, minimizing information exposure while maintaining ease of operation for authorized resources.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS7827407B2Scoped federations
Publication Date: 2010.11.02 MICROSOFT TECHNOLOGY LICENSING LLC
  • US7827407B2 patent drawing
  • US7827407B2 patent drawing
  • US7827407B2 patent drawing

AI summary

A scoped federation is described which is referenced by a unique identifier and messages relating to the federation include this unique identifier. The federation is scoped by rules which are stored associated with the unique identifier and upon receipt of a request containing the unique identifier, the related rules are checked to determine if the request is valid.