Trusted Client Security Factor Authorization via Pre-Registration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In client-server computing systems, servers face challenges in trusting client security factors obtained from unmanaged client machines, as these factors can be inaccurate or falsified, making reliable authorization decisions difficult.

Innovation Solution

The implementation of trusted client security factor-based authorizations, where client machines are pre-registered with a probabilistically difficult to predict machine registration digest, and client security factors are obtained and verified through a trusted channel, ensuring the accuracy and integrity of the security factors provided to the server.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If the server requires client machines to provide security factors for authorization, then the security control capability is improved, but the trustworthiness of the security factors deteriorates because client machines are unmanaged and can falsify information

Engineering Contradiction:
Improvesecurity control capabilityVSAvoidtrustworthiness of security factors
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent applies preliminary action by pre-registering client machines with the server before they attempt to access protected resources. During this pre-registration phase, the client machine's identity and initial security posture are established and verified. This preliminary registration creates a trusted foundation that allows the server to later rely on security factors reported by the client, resolving the trustworthiness issue while maintaining security control capability.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces a trusted intermediary component (such as a trusted platform module or hardware security module) that acts as a mediator between the client machine and the server. This intermediary securely stores and reports security factors, preventing the client from falsifying them. The intermediary serves as a trusted third party that the server can rely on, thereby improving the trustworthiness of security factors while maintaining authorization control.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If the server obtains detailed client security factors, then the authorization precision is improved, but the complexity of the authorization system deteriorates

Engineering Contradiction:
Improveauthorization precisionVSAvoidauthorization system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the authorization system into distinct functional components: a registration component for initial client setup, a security factor collection component for gathering security information, and an authorization component for making access decisions. This segmentation allows each component to focus on a specific task, improving authorization precision through specialized processing while managing overall system complexity through modular design.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent changes the parameters of security factors from simple binary states to multi-level detailed measurements. Instead of merely detecting whether a security patch is present, the system measures the version level, installation date, and compatibility status. This parameter enrichment improves authorization precision by providing granular control, while the structured approach to collecting and evaluating these parameters prevents excessive system complexity.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11777737B2Trusted client security factor-based authorizations at a server
Publication Date: 2023.10.03 ORACLE INT CORP
  • US11777737B2 patent drawing
  • US11777737B2 patent drawing
  • US11777737B2 patent drawing

AI summary

Trusted client security factor-based authorizations at a server. The techniques allow the server to authorize client requested operations to access a protected resource or service based on trusted client security factors that are obtained at client machines and provided to the server.