Trusted Service Privilege Model for Conferencing Systems

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing conferencing systems lack the ability to distinguish between user impersonations and trusted bots, limiting richer user experiences and real-time communication opportunities, as they cannot identify trusted requests and grant necessary privileges to automated services.

Innovation Solution

A real-time communications and conferencing system using SIP protocol with a 'superuser' privilege model, where a pre-configured service like a bot can join conferences, assume presenter roles, and hide from rosters, with specific protocol extensions enabling trusted services to bypass authentication and impose conference control rules.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If authentication is achieved using enterprise identity or system-supplied conference admission passcode, then security is maintained, but trusted conferencing services cannot operate without being challenged

Engineering Contradiction:
Improveauthentication securityVSAvoidtrusted service operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces a trusted service entity that acts as an intermediary between regular users and the conferencing system. This entity is pre-configured with special credentials that allow it to authenticate trusted bots without requiring standard authentication challenges, thereby resolving the contradiction between maintaining security and enabling seamless trusted service operation

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system changes the authentication parameter from standard user credentials to a special trusted service credential model. By introducing a hierarchical credential structure where trusted services have elevated privileges, the system maintains security for regular users while enabling frictionless access for authenticated trusted entities

Inventive Principle:
Principle #35Parameter changes

2Ease of operation

If the system cannot distinguish between user impersonations and trusted bots, then authentication simplicity is maintained, but richer conferencing services are limited

Engineering Contradiction:
Improveauthentication simplicityVSAvoidconferencing service capability
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The patent segments the user space into distinct categories: regular users, user impersonations, and trusted bots. By creating separate authentication and privilege pathways for each segment, the system maintains simplicity for regular authentication while enabling advanced capabilities for trusted services without conflating their requirements

Inventive Principle:
Principle #1Segmentation

3Loss of information

If trusted bots are visible in the conference roster, then transparency is improved, but the ability to remain invisible for automated services is lost

Engineering Contradiction:
Improveconference transparencyVSAvoidservice invisibility capability
Core Design Contradiction:
Loss of informationVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic visibility control where trusted services can adjust their presence in the conference roster based on operational requirements. The system allows trusted bots to be dynamically added to or removed from the visible roster, providing flexibility between transparency and invisibility modes depending on the specific service needs

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS9871799B2Enabling trusted conferencing services
Publication Date: 2018.01.16 MICROSOFT TECHNOLOGY LICENSING LLC
  • US9871799B2 patent drawing
  • US9871799B2 patent drawing
  • US9871799B2 patent drawing

AI summary

Architecture for providing a superuser privilege in a conferencing environment. A pre-configured entity such as a bot program receives special conferencing privileges. A request can be identified as originating from a trusted service and an associated predetermined set of privileges passed to the service. The trusted service can impersonate a user, and join a conference using its own identity or using the identity of a user. Conference control rules can be enforced on the trusted user (e.g., no other users can eject or mute this entity). Moreover, the trusted service can (optionally) hide itself from the conference roster to remain invisible to all participants.