Security Token Messaging Access Provisioning
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional electronic messaging systems require lengthy user account provisioning, preventing non-provisioned users from accessing or sending/receiving messages, which is particularly cumbersome for large organizations, governments, and military entities.
Innovation Solution
Implementing a system that uses an identity management system to provide just-in-time provisioning based on user information, where a security token validated by the identity management system allows users to send and receive messages without pre-provisioning, using SAML tokens for authentication and authorization, and dynamically determining security levels based on the user's environment.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional user account provisioning is implemented, then authorization data can be stored in the messaging system, but the provisioning process takes days and prevents immediate access
Solution Approach 1:
The identity management system performs preliminary authentication and generates security tokens containing authorization data before the user actually accesses the messaging system. This pre-provisioning of authorization credentials in token form eliminates the need for time-consuming account setup in the messaging system itself, allowing users to immediately access messaging services upon token validation.
Solution Approach 2:
The patent introduces an identity management system as an intermediary between users and the messaging system. This intermediary handles authentication and generates security tokens that encapsulate all necessary authorization data, which then serves as a portable credential that users can present to the messaging system without requiring pre-existing accounts or lengthy provisioning processes.
2Ease of operation
If user accounts are pre-provisioned with authorization data, then users can access messaging services, but the provisioning process is lengthy and complex for large organizations
Solution Approach 1:
Users authenticate with the identity management system using their existing organizational credentials and automatically receive security tokens without requiring manual account creation or administration in the messaging system. The system automatically validates tokens and provisions access rights on-demand, eliminating the need for users to wait for administrative provisioning and enabling immediate self-service access to messaging services.
Solution Approach 2:
The patent changes the fundamental parameter of user identification from requiring pre-configured account credentials in the messaging system to using portable security tokens generated by an external identity management system. This parameter change transforms the access model from static pre-provisioning to dynamic token-based authentication, dramatically reducing setup time while maintaining security.
3Reliability
If authorization data is stored in the messaging system, then user authentication is enabled, but duplicate authorization data must be maintained across systems
Solution Approach 1:
The patent extracts authorization data from the messaging system's user account structure and consolidates it into security tokens generated by the identity management system. Instead of storing authorization data in multiple locations (messaging system and identity management system), the token serves as a portable, self-contained credential that users present to the messaging system, eliminating the need for duplicate data storage and synchronization between systems.
4Productivity
If security tokens are validated on-demand, then immediate messaging access is enabled, but real-time verification of user authorization is required
Solution Approach 1:
The identity management system performs preliminary authentication and generates security tokens containing all necessary authorization data before users access the messaging system. The tokens include pre-computed authorization information that allows the messaging system to validate user credentials locally without requiring real-time connection to the identity management system, thus enabling immediate access while maintaining verification security.
Data Source
AI summary
A computer program product for processing a message is provided. The computer program product comprises a computer readable storage medium having program instructions embodied therewith. The program instructions readable by a processing circuit cause the processing circuit to perform a method. The method validates a security token for a user. The method allows the user to compose a message. Based on the security token, the method verifies that the user is authorized to send the message to an intended recipient of the message and that a security level of the message is at or below a security level of the user.


