Secure Communications Agent for Granular Application Delegation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users face challenges in securely communicating sensitive information over the Internet due to the complexity of cryptographic infrastructure and the risk of trust exploitation by third-party organizations providing cryptographic functionality, as well as the potential security risks of allowing third-party applications access to cryptographic keys.

Innovation Solution

A secure communications infrastructure that allows users to delegate permissions to third-party applications at a granular level, with an agent component acting as an intermediary between third-party applications and the core infrastructure, preventing access to security-specific data and maintaining system security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Extent of automation

If third-party applications are allowed direct access to cryptographic keys to perform operations on behalf of users, then application functionality and automation are improved, but security risk increases due to potential key exposure

Engineering Contradiction:
Improveapplication automationVSAvoidsecurity
Core Design Contradiction:
Extent of automationVSReliability

Solution Approach 1:

The patent introduces an agent component as an intermediary layer between third-party applications and the cryptographic infrastructure. The agent receives requests from applications, validates them against delegation policies, and performs cryptographic operations using keys that never leave the secure infrastructure. This mediator architecture enables application automation while maintaining security by ensuring applications never directly access cryptographic keys.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If cryptographic infrastructure is made transparent and easy to use, then ease of operation is improved, but trust requirements increase as users must trust the infrastructure providers

Engineering Contradiction:
ImprovetransparencyVSAvoidtrust risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the trust requirement from the cryptographic infrastructure providers and relocates it to the user's own agent component. By making the agent a user-controlled element rather than a provider-controlled service, the system maintains transparency and ease of use while eliminating the need to trust third-party infrastructure providers with cryptographic operations.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If granular delegation permissions are implemented to control application access, then security is improved, but system complexity increases due to permission management overhead

Engineering Contradiction:
ImprovesecurityVSAvoidpermission management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements preliminary action by requiring users to configure granular delegation permissions in advance, before any application requests access. The agent stores these pre-defined policies and automatically evaluates them when applications make requests. This approach provides fine-grained security control while simplifying runtime operations, as the complexity of permission management is resolved beforehand rather than during each cryptographic operation.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10819709B1Authorizing delegated capabilities to applications in a secure end-to-end communications system
Publication Date: 2020.10.27 SYMPHONY COMMUNICATION SERVICES HOLDINGS LLC
  • US10819709B1 patent drawing
  • US10819709B1 patent drawing
  • US10819709B1 patent drawing

AI summary

An organization that wishes its messages to be secure (the “communicating organization”) uses services of a secure communications infrastructure to securely exchange communications among its users. The secure communications infrastructure allows granting to third-party applications the permission to act on behalf of the users when using the secure communications infrastructure. This delegation may be accomplished at a very granular level, specifying the particular applications that are authorized to act on behalf of a user, the particular operations that those applications are authorized to perform, and/or in which contexts the applications may perform the operations. An agent component acts as an intermediary between third-party applications and the core of the secure communications infrastructure. This permits the third-party application to take actions on behalf of the user, while also preventing the third-party applications from obtaining the security-specific data that could lead to a breach of security.