Auditable Mechanism for Internal Service Transactions

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cloud computing environments face security risks due to lack of transparency and accountability in internal services' access to customer data, particularly through full trust service-to-service calls which can lead to unauthorized changes and security breaches.

Innovation Solution

Implementing a cloud security module that registers internal services with an assistant service, configures the assistant service to perform auditable cloud computing actions, and allows the assistant service to perform these actions on behalf of the internal service based on existing permissions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If full trust service-to-service calls are used, then service operation simplicity is improved, but security reliability deteriorates due to lack of accountability and transparency

Engineering Contradiction:
Improveservice operation simplicityVSAvoidsecurity reliability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces an intermediary authentication and authorization mechanism between services. Instead of direct full-trust calls, services must go through this intermediary layer that verifies identities, checks permissions, and logs actions. This mediator maintains operational simplicity while enforcing security protocols.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements feedback mechanisms through authentication responses, permission verification results, and action logging. These feedback loops provide transparency about service interactions, allowing monitoring and auditing while maintaining the simplified service-to-service communication architecture.

Inventive Principle:
Principle #23Feedback

2Productivity

If internal services have unrestricted access to tenant data, then service productivity is improved, but loss of information worsens due to unauthorized changes and data breaches

Engineering Contradiction:
Improveservice productivityVSAvoidunauthorized data changes
Core Design Contradiction:
ProductivityVSLoss of information

Solution Approach 1:

The patent applies local quality by granting services access to tenant data selectively based on their specific permissions and requirements. Each service receives only the minimal necessary access rights for its function, rather than unrestricted access. This is enforced through permission verification at the data access layer.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent performs preliminary authentication and authorization actions before allowing any data access. Services must first prove their identity and obtain explicit permission for each data operation. This preliminary verification prevents unauthorized changes while maintaining efficient service operation.

Inventive Principle:
Principle #10Preliminary action

3Device complexity

If service-to-service calls lack transparency, then device complexity is reduced, but measurement precision worsens due to inability to audit actions

Engineering Contradiction:
Improvesystem architecture simplicityVSAvoidaction auditing capability
Core Design Contradiction:
Device complexityVSMeasurement precision

Solution Approach 1:

The authentication and authorization system operates autonomously as a self-service mechanism. It automatically verifies service identities, checks permissions, and logs actions without requiring manual intervention or complex external monitoring systems. This self-service approach maintains architectural simplicity while providing comprehensive auditing capability.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS20250110779A1Auditable mechanism for internal services to transact on tenant entities
Publication Date: 2025.04.03 MICROSOFT TECHNOLOGY LICENSING LLC
  • US20250110779A1 patent drawing
  • US20250110779A1 patent drawing
  • US20250110779A1 patent drawing

AI summary

Example aspects include techniques for providing an auditable mechanism for internal services to transact on tenant entities. These techniques may include receiving, from an internal service, by an assistant service, a service request to perform a cloud computing action over tenant data of a tenant of a cloud computing environment. In addition, the techniques may include identifying, by the assistant service, an existing principal of the assistant service within the tenant and possession of an existing permission associated with performing the cloud computing action within the tenant of the cloud computing environment. Further, the techniques may include performing the cloud computing action on behalf of the internal service based on identifying the existing principal and possession of the existing permission.