Structure-Based Authentication for Granular Resource Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing single sign-on (SSO) techniques rely on predefined roles to manage resource access, which can lead to inflexibility and mismatches between user permissions and resource structures, necessitating coordinated role definitions across identity and service provider systems.

Innovation Solution

An identity provider system determines a permission indication based on the structure of resources at the service provider system, specifying the subset of resources a user is permitted to access, allowing for flexible and granular permission management without preconfigured roles.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If predefined roles are used to manage resource access, then access control is simplified, but flexibility and precision in permission allocation deteriorate

Engineering Contradiction:
Improveaccess control simplicityVSAvoidpermission allocation flexibility
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The patent changes the parameter of permission representation from fixed role-based categories to granular, structure-based parameters. Instead of assigning users to predefined roles, the system defines permissions by specifying exact portions of resource structures (tables, fields, rows) that users can access, allowing flexible and precise control over data access rights.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent segments resource access permissions into fine-grained units corresponding to specific portions of the resource structure. Rather than granting access at the role level, the system divides permissions down to the level of individual tables, fields, and rows, enabling precise control over which specific data elements users can access.

Inventive Principle:
Principle #1Segmentation

2Device complexity

If role-based access control is used, then system complexity is reduced, but alignment with actual resource structure deteriorates

Engineering Contradiction:
Improveaccess control system complexityVSAvoidpermission-resource structure alignment
Core Design Contradiction:
Device complexityVSManufacturing precision

Solution Approach 1:

The patent inverts the traditional role-based approach by starting with the resource structure itself and deriving permissions from it, rather than starting with predefined roles and mapping resources to them. This inversion ensures that permissions naturally align with the actual database structure without requiring coordinated role definitions across multiple systems.

Inventive Principle:
Principle #13The other way round (Inversion)

3Productivity

If single sign-on uses predefined roles, then authentication is streamlined, but permission precision deteriorates

Engineering Contradiction:
Improveauthentication efficiencyVSAvoidpermission specification accuracy
Core Design Contradiction:
ProductivityVSMeasurement precision

Solution Approach 1:

The patent introduces dynamic permission specification where the permission indication can define different portions of the resource structure based on the authenticated user's characteristics. This allows the system to maintain efficient single sign-on authentication while enabling precise, user-specific permission allocation that adapts to individual user needs rather than relying on static role definitions.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS12417265B2Authentication system
Publication Date: 2025.09.16 PAYCASSO VERIFY
  • US12417265B2 patent drawing
  • US12417265B2 patent drawing
  • US12417265B2 patent drawing

AI summary

Methods performed by an identity provider system, a service provider system and a user device are provided. The identity provider system performs an authentication process to confirm an identity of a user. In a case that the identity of the user is confirmed by the authentication process, the identity provider system determines a portion of resources made available at the service provider system that the user is allocated permission to access and generates a permission indication. The permission indication defines a portion of a structure of the resources corresponding to the portion of the resources which the user is permitted to access. The user can access resources made available by the service provider system which are both requested by user device via a resource request and permitted to be accessed by the user according to the permission indication.