Security Token Messaging Access Provisioning

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional electronic messaging systems require lengthy user account provisioning, preventing non-provisioned users from accessing or sending/receiving messages, which is particularly cumbersome for large organizations, governments, and military entities.

Innovation Solution

Implementing a system that uses an identity management system to provide just-in-time provisioning based on user information, where a security token validated by the identity management system allows users to send and receive messages without pre-provisioning, using SAML tokens for authentication and authorization, and dynamically determining security levels based on the user's environment.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional user account provisioning is implemented, then authorization data can be stored in the messaging system, but the provisioning process takes days and prevents immediate access

Engineering Contradiction:
Improveauthorization data storageVSAvoidprovisioning time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The identity management system performs preliminary authentication and generates security tokens containing authorization data before the user actually accesses the messaging system. This pre-provisioning of authorization credentials in token form eliminates the need for time-consuming account setup in the messaging system itself, allowing users to immediately access messaging services upon token validation.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an identity management system as an intermediary between users and the messaging system. This intermediary handles authentication and generates security tokens that encapsulate all necessary authorization data, which then serves as a portable credential that users can present to the messaging system without requiring pre-existing accounts or lengthy provisioning processes.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If user accounts are pre-provisioned with authorization data, then users can access messaging services, but the provisioning process is lengthy and complex for large organizations

Engineering Contradiction:
Improvemessaging accessVSAvoidaccount setup time
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

Users authenticate with the identity management system using their existing organizational credentials and automatically receive security tokens without requiring manual account creation or administration in the messaging system. The system automatically validates tokens and provisions access rights on-demand, eliminating the need for users to wait for administrative provisioning and enabling immediate self-service access to messaging services.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent changes the fundamental parameter of user identification from requiring pre-configured account credentials in the messaging system to using portable security tokens generated by an external identity management system. This parameter change transforms the access model from static pre-provisioning to dynamic token-based authentication, dramatically reducing setup time while maintaining security.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If authorization data is stored in the messaging system, then user authentication is enabled, but duplicate authorization data must be maintained across systems

Engineering Contradiction:
Improveuser authenticationVSAvoidauthorization data management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts authorization data from the messaging system's user account structure and consolidates it into security tokens generated by the identity management system. Instead of storing authorization data in multiple locations (messaging system and identity management system), the token serves as a portable, self-contained credential that users present to the messaging system, eliminating the need for duplicate data storage and synchronization between systems.

Inventive Principle:
Principle #2Taking out (Extraction)

4Productivity

If security tokens are validated on-demand, then immediate messaging access is enabled, but real-time verification of user authorization is required

Engineering Contradiction:
Improvemessaging access speedVSAvoidreal-time verification
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The identity management system performs preliminary authentication and generates security tokens containing all necessary authorization data before users access the messaging system. The tokens include pre-computed authorization information that allows the messaging system to validate user credentials locally without requiring real-time connection to the identity management system, thus enabling immediate access while maintaining verification security.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9525676B2Message content adjudication based on security token
Publication Date: 2016.12.20 RAYTHEON CO
  • US9525676B2 patent drawing
  • US9525676B2 patent drawing
  • US9525676B2 patent drawing

AI summary

A computer program product for processing a message is provided. The computer program product comprises a computer readable storage medium having program instructions embodied therewith. The program instructions readable by a processing circuit cause the processing circuit to perform a method. The method validates a security token for a user. The method allows the user to compose a message. Based on the security token, the method verifies that the user is authorized to send the message to an intended recipient of the message and that a security level of the message is at or below a security level of the user.