Session Credential Delegation for Secure Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional techniques for permission delegation and reliable authentication in computing networks are cumbersome and pose unnecessary risks, particularly when granting temporary or limited access to computing resources.
Innovation Solution
The system allows users to delegate access privileges by generating a session credential that includes authentication information, policies, and metadata, ensuring that delegatees have no more access than the delegator, with policies checked at the time of access requests and enabling multifactor authentication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If conventional permission delegation techniques are used, then access can be granted to users, but the process becomes cumbersome and increases security risk
Solution Approach 1:
The patent introduces a session credential as an intermediary mechanism between the delegator and the delegatee. This session credential encapsulates all necessary access information and policies, allowing the delegatee to access resources without directly receiving permanent credentials from the delegator. The intermediary session credential simplifies the delegation process while maintaining security through temporary, scoped access rights.
Solution Approach 2:
The system performs preliminary authentication of the delegator and establishment of session credentials before any access is granted. Policies are pre-defined and encoded into the session credential, including time limits, resource scope, and access conditions. This preliminary setup eliminates the need for ongoing manual permission management and reduces security risks by ensuring all access is pre-authorized and time-bound.
2Adaptability or versatility
If temporary access is granted to computing resources, then access flexibility is improved, but authentication reliability becomes more challenging
Solution Approach 1:
The session credential incorporates dynamic time-based policies that automatically expire after a predetermined duration. The access rights are not static but dynamically adjust based on the session's temporal scope. This dynamic approach enables flexible temporary access while maintaining authentication reliability through automated expiration, eliminating the need for manual revocation and ensuring that temporary access cannot persist indefinitely.
Solution Approach 2:
The session credential acts as a nested container that encapsulates multiple layers of information: the delegator's credentials, the delegatee's identity, the specific resources to access, the time limits, and the policies. This nested structure organizes complex access control information into a single manageable unit, enabling flexible temporary access while maintaining reliability through centralized validation of all nested components.
3Ease of operation
If access privileges are delegated, then user access is enabled, but the complexity of policy management increases
Solution Approach 1:
The patent extracts the complex policy management functionality from the delegation process and embeds it directly into the session credential. All policies, including time limits, resource scopes, and access conditions, are extracted as predefined parameters that the system automatically enforces. This extraction eliminates the need for manual policy configuration during delegation, simplifying the user experience while reducing overall system complexity through automated policy application.
Solution Approach 2:
The session credential serves multiple functions simultaneously: it authenticates the delegator, identifies the delegatee, defines the scope of access, establishes time limits, and encodes policies. This multi-functional design consolidates what would otherwise require multiple separate systems and processes into a single unified mechanism, making access granting easier while reducing policy management complexity through consolidation.
4Reliability
If multifactor authentication is required for different access types, then authentication security is improved, but the authentication process becomes more time-consuming
Solution Approach 1:
The system performs multifactor authentication as a preliminary action during session credential generation, rather than requiring it for every subsequent access request. Once the session credential is established with embedded authentication information, all subsequent access requests can use the pre-authenticated credential, significantly reducing authentication time while maintaining the security benefits of multifactor authentication.
Solution Approach 2:
The session credential enables continuous access without repeated authentication challenges. The useful action of authentication is performed once during session creation and then continues to validate access rights throughout the session duration. This continuous validation approach maintains authentication security through ongoing policy enforcement while eliminating repeated time-consuming authentication steps.
Data Source
AI summary
Systems and methods for controlling access to one or more computing resources relate to generating session credentials that can be used to access the one or more computing resources. Access to the computing resources may be governed by a set of policies and requests for access made using the session credentials may be fulfilled depending on whether they are allowed by the set of policies. The session credentials themselves may include metadata that may be used in determining whether to fulfill requests to access the one or more computing resources. The metadata may include permissions for a user of the session credential, claims related to one or more users, and other information.


