Shared Memory Workspace Permissions for Secure Multi-Device Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems do not allow users to share workspaces that include multiple types of files and applications, and they lack secure hosting and interaction capabilities.

Innovation Solution

A method for allocating a shared memory space on a client device to instantiate a user interface representing dynamic application objects, allowing users to define access rights and interact with a collaborative workspace, which can be accessed by multiple devices and hosted securely using barcodes and canvas codes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If users share workspaces with multiple devices, then collaboration capability is improved, but security control becomes more complex

Engineering Contradiction:
Improvecollaboration capabilityVSAvoidsecurity control complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments security control into device-specific access rights, where each electronic device is granted individual permissions (read, write, execute) rather than treating all devices uniformly. This allows fine-grained security management while supporting multi-device collaboration.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary authentication and authorization actions before allowing workspace access. Devices must be authenticated and granted explicit access rights prior to interacting with the shared memory space, establishing security controls in advance rather than managing them dynamically during collaboration.

Inventive Principle:
Principle #10Preliminary action

2Adaptability or versatility

If multiple device types access shared memory, then system versatility is improved, but access control management becomes more difficult

Engineering Contradiction:
Improvesystem versatilityVSAvoidaccess control management
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent implements a universal access control framework that works across diverse device types (smartphones, tablets, computers, wearables). The same authentication and authorization mechanisms apply to all devices regardless of platform, simplifying access control management while maintaining broad compatibility.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system changes access control parameters dynamically based on device characteristics and user roles. Different devices can be assigned different permission levels (read-only, read-write, execute) and access conditions, allowing flexible management of diverse device access without requiring separate control systems for each device type.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If secure hosting is implemented, then security is improved, but system complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary authentication service that mediates between devices and the shared memory space. This intermediary handles security verification, permission checking, and access grant/revocation, centralizing security functions and reducing the complexity burden on individual devices and the overall system architecture.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20250350601A1Methods and apparatus for establishing shared memory spaces for data access and distribution
Publication Date: 2025.11.13 POSTOAK TODAY LLC
  • US20250350601A1 patent drawing
  • US20250350601A1 patent drawing
  • US20250350601A1 patent drawing

AI summary

In some implementations, methods and apparatuses herein relate to generating shared memory spaces that can share files or applications between users and between user devices. For example, a processor can allocate a first portion of a memory of a client device to serve as a shared memory space for at least one dynamic application object, and instantiating a user interface on a display associated with the client device. The user interface can be based on a content of the shared memory space and representing the at least one dynamic application object. A processor can define access rights for a user of a second electronic device for receiving a copy of the instantiated user interface. The processor can define user rights for the user for use of the at least one dynamic application object with the second electronic device. The at least one dynamic application object can be a data file or a live user experience.