Access Management Tags for Flexible Resource Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Access management systems face challenges in efficiently granting and updating access to resources, as existing access control lists are inflexible and difficult to manage, making it hard for administrators to quickly grant access to new resources or update access for existing ones.

Innovation Solution

The implementation of an access management system that uses tags, which are metadata key-value pairs, to control access by assigning them to users and resources, allowing administrators to easily manage access by creating, modifying, or removing tags, and using them to determine access privileges.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If access control lists are used to control access to resources, then access security is maintained, but administrative flexibility and ease of managing access rights deteriorate

Engineering Contradiction:
Improveadministrative flexibilityVSAvoidaccess management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent transforms the traditional access control approach by changing the parameter representation from detailed access control lists to simplified tag metadata. Instead of managing complex permission sets, administrators assign simple key-value tag pairs to users and resources, fundamentally altering how access rights are defined and managed.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The tag-based system serves multiple functions simultaneously: it provides access control, enables resource categorization, supports auditing, and facilitates policy management. A single tag assignment can influence multiple access decisions across different resources, reducing the need for separate management mechanisms.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Productivity

If traditional access control lists are used, then access security is ensured, but the time required to grant or update access rights increases

Engineering Contradiction:
Improveaccess management efficiencyVSAvoidtime to grant or update access
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

Administrators pre-define tag schemas and assign tags to users and resources in advance. When access decisions need to be made, the system has already processed and organized the tag information, enabling rapid access control evaluations without requiring real-time complex list processing.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent creates simplified tag representations that copy the essential access control information from complex access control lists. These tag copies can be quickly processed and compared, significantly reducing the computational and temporal overhead of access management operations.

Inventive Principle:
Principle #26Copying

3Adaptability or versatility

If access control lists are implemented, then comprehensive access control is achieved, but the flexibility to quickly update access rights deteriorates

Engineering Contradiction:
Improveaccess update flexibilityVSAvoidease of updating access
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The tag-based system enables dynamic access management where tags can be easily added, removed, or modified without restructuring the entire access control framework. This dynamic approach allows administrators to quickly adapt access rights in response to changing organizational needs while maintaining system integrity.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS11368403B2Access management tags
Publication Date: 2022.06.21 AMAZON TECH INC
  • US11368403B2 patent drawing
  • US11368403B2 patent drawing
  • US11368403B2 patent drawing

AI summary

Tags may be used in decisions by an access management service regarding access of computing resources (“resources”) by principals (e.g., users, roles, etc.). The tags may also be used to determine cost information, for grouping resources and/or principals, and for other reasons. The tags may be assigned to principals, to resources, or both. The resource may be a virtual or physical type of computing resource. Tags may be metadata, which may include a key-value pair. Tags may include email addresses, cost centers, project identifiers, location, team name, etc. The value may be a number, letters, or a combination of both. In some embodiments, the values may be limited to certain numbers or bytes, and some numbers and/or letter combinations may be excluded for special use.