Trusted Authority Credentials for Bidirectional Remote Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing access control systems lack system-level trust and customizable credentials, leading to inefficient and resource-intensive authentication processes that require multiple certificates/credentials for different types of resource access, and do not support bidirectional authentication.
Innovation Solution
Establish a secure channel between devices using system-specific trusted authorities, enabling public key mutual authentication and system-specific user credentials to authorize bidirectional access to both physical and logical resources, with customizable payloads encoding access rights.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If multiple certificates and credentials are used for different types of resource access, then access control coverage is improved, but system complexity and resource consumption increase
Solution Approach 1:
The patent implements a universal credential structure that can represent multiple types of access rights (physical access, logical access, data access) within a single credential. The credential contains a payload with multiple access right entries, each specifying different resource types and permission levels. This allows one credential to replace multiple traditional certificates while maintaining comprehensive access control coverage across diverse resource types.
2Adaptability or versatility
If multiple certificates and credentials are used for different types of resource access, then access control coverage is improved, but resource consumption increases
Solution Approach 1:
The patent merges multiple access right attributes into a single credential payload structure. Instead of exchanging multiple separate certificates for different resource types, the system combines physical access rights, logical access rights, and data access rights into one unified credential. This reduction in the number of authentication objects directly decreases processing overhead and resource consumption during authentication operations.
3Adaptability or versatility
If traditional authentication protocols are used, then compatibility is maintained, but bidirectional authentication and system-level trust are not achieved
Solution Approach 1:
The patent introduces a system-level trusted authority as an intermediary that issues credentials with embedded access rights. This trusted authority acts as a mediator between the access control system and resource owners, providing verifiable proof of authorization through cryptographically signed credentials. The trusted authority's public key is embedded in the credential, enabling both parties to verify authentication without requiring pre-shared secrets or complex trust negotiations.
4Ease of manufacture
If unidirectional authentication is implemented, then implementation simplicity is maintained, but mutual access control is not achieved
Solution Approach 1:
The patent inverts the traditional authentication model by embedding the verifier's public key and access right requirements directly into the credential itself. Instead of the server maintaining a database of authorized clients, the client's credential contains the server's public key and specifies what resources the client is authorized to access. This allows the client to independently verify server identity and enforce access rights, enabling bidirectional authentication where both parties can verify each other's credentials and enforce access control policies.
Data Source
AI summary
Methods and systems for establishing a system specific trust system are provided. The methods and systems establish a secure channel between a first device and a second device using a system specific trusted authority. The methods and systems determine, by the first device, using a first certificate associated with the second device, a first set of access rights of the second device and determine, by the second device, using a credential associated with the first device, a second set of access rights of the first device.


