Session Credential Delegation for Secure Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional techniques for permission delegation and reliable authentication in computing networks are cumbersome and pose unnecessary risks, particularly when granting temporary or limited access to computing resources.

Innovation Solution

The system allows users to delegate access privileges by generating a session credential that includes authentication information, policies, and metadata, ensuring that delegatees have no more access than the delegator, with policies checked at the time of access requests and enabling multifactor authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If conventional permission delegation techniques are used, then access can be granted to users, but the process becomes cumbersome and increases security risk

Engineering Contradiction:
Improveease of permission delegationVSAvoidsecurity risk
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a session credential as an intermediary mechanism between the delegator and the delegatee. This session credential encapsulates all necessary access information and policies, allowing the delegatee to access resources without directly receiving permanent credentials from the delegator. The intermediary session credential simplifies the delegation process while maintaining security through temporary, scoped access rights.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary authentication of the delegator and establishment of session credentials before any access is granted. Policies are pre-defined and encoded into the session credential, including time limits, resource scope, and access conditions. This preliminary setup eliminates the need for ongoing manual permission management and reduces security risks by ensuring all access is pre-authorized and time-bound.

Inventive Principle:
Principle #10Preliminary action

2Adaptability or versatility

If temporary access is granted to computing resources, then access flexibility is improved, but authentication reliability becomes more challenging

Engineering Contradiction:
Improveaccess flexibilityVSAvoidauthentication reliability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The session credential incorporates dynamic time-based policies that automatically expire after a predetermined duration. The access rights are not static but dynamically adjust based on the session's temporal scope. This dynamic approach enables flexible temporary access while maintaining authentication reliability through automated expiration, eliminating the need for manual revocation and ensuring that temporary access cannot persist indefinitely.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The session credential acts as a nested container that encapsulates multiple layers of information: the delegator's credentials, the delegatee's identity, the specific resources to access, the time limits, and the policies. This nested structure organizes complex access control information into a single manageable unit, enabling flexible temporary access while maintaining reliability through centralized validation of all nested components.

Inventive Principle:
Principle #7Nested doll (Nesting)

3Ease of operation

If access privileges are delegated, then user access is enabled, but the complexity of policy management increases

Engineering Contradiction:
Improveease of access grantingVSAvoidpolicy management complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent extracts the complex policy management functionality from the delegation process and embeds it directly into the session credential. All policies, including time limits, resource scopes, and access conditions, are extracted as predefined parameters that the system automatically enforces. This extraction eliminates the need for manual policy configuration during delegation, simplifying the user experience while reducing overall system complexity through automated policy application.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The session credential serves multiple functions simultaneously: it authenticates the delegator, identifies the delegatee, defines the scope of access, establishes time limits, and encodes policies. This multi-functional design consolidates what would otherwise require multiple separate systems and processes into a single unified mechanism, making access granting easier while reducing policy management complexity through consolidation.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Reliability

If multifactor authentication is required for different access types, then authentication security is improved, but the authentication process becomes more time-consuming

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs multifactor authentication as a preliminary action during session credential generation, rather than requiring it for every subsequent access request. Once the session credential is established with embedded authentication information, all subsequent access requests can use the pre-authenticated credential, significantly reducing authentication time while maintaining the security benefits of multifactor authentication.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The session credential enables continuous access without repeated authentication challenges. The useful action of authentication is performed once during session creation and then continues to validate access rights throughout the session duration. This continuous validation approach maintains authentication security through ongoing policy enforcement while eliminating repeated time-consuming authentication steps.

Inventive Principle:
Principle #20Continuity of useful action

Data Source

PatentUS11102189B2Techniques for delegation of access privileges
Publication Date: 2021.08.24 AMAZON TECH INC
  • US11102189B2 patent drawing
  • US11102189B2 patent drawing
  • US11102189B2 patent drawing

AI summary

Systems and methods for controlling access to one or more computing resources relate to generating session credentials that can be used to access the one or more computing resources. Access to the computing resources may be governed by a set of policies and requests for access made using the session credentials may be fulfilled depending on whether they are allowed by the set of policies. The session credentials themselves may include metadata that may be used in determining whether to fulfill requests to access the one or more computing resources. The metadata may include permissions for a user of the session credential, claims related to one or more users, and other information.