Secondary Device Authorization for Cloud Resource Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cloud-based network environments lack the configurability and customization necessary to effectively manage access to enterprise resources at a device level, posing challenges in protecting sensitive information and services.

Innovation Solution

A system where a client-side application on a client device authenticates user credentials and device identifiers, requiring a secondary client device to be in communication for access, using distribution rules to ensure compliance and providing authorization credentials for secure access to resources stored on an enterprise server or locally.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If cloud-based network environments are used to store and access enterprise resources, then accessibility and flexibility are improved, but security and device-level access control are worsened

Engineering Contradiction:
ImproveaccessibilityVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces an authorization service as an intermediary between client devices and enterprise resources. This service verifies authorization credentials and enforces distribution rules, acting as a mediator that maintains security while enabling cloud-based accessibility. The authorization service checks whether required secondary devices are present and validates credentials before granting access to resources.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the authentication process into multiple components: primary device identification, secondary device verification, credential validation, and distribution rule enforcement. This segmentation allows each component to be independently managed and verified, enhancing security while maintaining cloud accessibility.

Inventive Principle:
Principle #1Segmentation

2Reliability

If traditional firewalls and VPN tunnels are used for access control, then network-level security is improved, but device-level access control is worsened

Engineering Contradiction:
Improvenetwork securityVSAvoiddevice-level control
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent transitions from network-level access control to device-level access control by introducing a new dimension of verification. Instead of controlling access at the network boundary, the system verifies the presence and authorization status of specific secondary devices (such as mobile phones) in conjunction with primary devices (such as laptops), enabling granular device-level control.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Adaptability or versatility

If cloud-based data services are used, then resource accessibility is improved, but device-level access management capability is worsened

Engineering Contradiction:
Improveresource accessibilityVSAvoidaccess management capability
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The authorization service implements feedback mechanisms by continuously monitoring the presence of secondary devices and validating authorization credentials before granting access. The system provides feedback to client applications about authorization status and enforces distribution rules dynamically, enabling effective access management in cloud environments.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS9401915B2Secondary device as key for authorizing access to resources
Publication Date: 2016.07.26 OMNISSA LLC
  • US9401915B2 patent drawing
  • US9401915B2 patent drawing
  • US9401915B2 patent drawing

AI summary

A secondary device may be used to provide access to resources to a primary device. Upon receiving an authorization indication at a device, a registration key based on the authorization indication, a user identifier, and a property of the device may be created. Upon determining whether access to at least one resource is permitted according to the registration key the device may be permitted to access the at least one resource.