Security Agent Intercepts Authorization Requests for Granular Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current computer security systems often grant excessive privilege rights to users to allow applications to function correctly, compromising security and potentially leading to accidental tampering or malicious access to resources.

Innovation Solution

A computer device with a security system that includes an agent capable of intercepting and redirecting authorization requests, using a redirection mechanism to selectively allow or deny access based on independent URI authorization rules, thereby enabling higher-level access rights while maintaining security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If higher-level access rights (e.g., local administrator rights) are granted to users to allow applications to execute correctly, then application functionality is improved, but security of the computer device deteriorates

Engineering Contradiction:
Improveapplication functionalityVSAvoidsecurity risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the authorization process into two independent parts: the security system handles standard authorization requests with basic privileges, while the agent handles specific authorization requests requiring higher-level access rights. This segmentation allows applications to function with minimal privileges while maintaining security, as the agent only activates when specifically needed and can selectively allow or deny elevated access.

Inventive Principle:
Principle #1Segmentation

2Ease of operation

If additional privilege rights are granted to all members of a user group to ensure application operation, then ease of operation is improved, but reliability deteriorates

Engineering Contradiction:
Improveuser accessibilityVSAvoidsystem security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent applies local quality by giving different authorization capabilities to different components: the security system provides standard authorization for most operations, while the agent provides specialized authorization for specific resources requiring higher privileges. This allows ordinary users to access most resources with standard privileges while maintaining the ability to access specific resources with elevated rights when needed, without compromising overall system security.

Inventive Principle:
Principle #3Local quality

3Object-affected harmful factors

If a redirection mechanism is added to selectively control authorization requests, then security is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity protectionVSAvoidsystem architecture
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent introduces an agent as an intermediary component that sits between applications and the security system. The agent intercepts specific authorization requests, redirects them through a controlled process, and returns results to the security system. This intermediary approach enhances security by adding a layer of selective control without fundamentally restructuring the entire security architecture, as it works within the existing security framework rather than replacing it.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS9996703B2Computer device and method for controlling access to a resource via a security system
Publication Date: 2018.06.12 AVECTO
  • US9996703B2 patent drawing
  • US9996703B2 patent drawing
  • US9996703B2 patent drawing

AI summary

A computer system 300 contains an agent 303 which modifies the ordinary behaviour of a native security system 103, such as to allow security decisions with alternate granularity or an alternate set of access rights. The agent 303 intercepts authorisation requests made by applications 109 for resources 110 identified by URIs 111 and sends amended requests to the security system 103. An alternate authorisation mechanism 307 of the agent 303 is invoked by the security system 103, whereupon the agent 303 may selectively allow or deny the request according to the originally presented URI 111.