Authorization Service Handshake for Cloud Resource Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Managing access to online services for client resources such as servers and virtual machines is complex, as they often require different access levels and multiple credentials, and updating credentials across resources is cumbersome.
Innovation Solution
An authorization service that issues a one-time-use activation code to client resources, allowing them to register and obtain an authorization token for accessing online services, with an authorization agent installed to manage and refresh tokens, while detecting and differentiating cloned resources.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If client credentials are distributed to client resources for access to online services, then client resources can access online services, but managing and updating credentials across multiple resources becomes complex and troublesome
Solution Approach 1:
The patent introduces an authorization service as an intermediary between the online service and client resources. This service manages credentials centrally and issues authorization tokens to client resources, eliminating the need to distribute and manage client credentials across multiple resources. The authorization service acts as a mediator that handles authentication and authorization, simplifying credential management while maintaining security.
Solution Approach 2:
The patent creates authorization tokens that are copies or representations of client credentials. Instead of distributing actual client credentials to multiple resources, the system generates token copies that grant access rights. These tokens can be safely distributed and revoked without affecting the original credentials, making credential management much easier.
2Adaptability or versatility
If multiple sets of client credentials are provided for accessing multiple online services, then client resources can access multiple services, but the complexity of managing multiple credential sets increases
Solution Approach 1:
The authorization service provides a universal authorization mechanism that works across multiple online services. Instead of requiring separate credential sets for each service, the system issues authorization tokens that can be used to access multiple services. This multi-functional approach allows client resources to access various online services while managing a single set of authorization tokens, significantly reducing management complexity.
3Reliability
If client credentials are updated, then security is improved, but all client resources using those credentials must be updated, which is cumbersome
Solution Approach 1:
The system uses authorization tokens as copies of credential authority. When credentials need to be updated or revoked, the authorization service can simply invalidate the corresponding authorization tokens without affecting the original client credentials. This allows rapid security updates by regenerating or revoking tokens, saving significant time compared to updating credentials across all client resources.
Solution Approach 2:
The authorization service implements a mechanism where old or compromised authorization tokens can be discarded (revoked) and new tokens can be issued. This allows the system to quickly respond to security incidents by invalidating specific tokens without needing to update all client resources, enabling rapid credential rotation and recovery.
Data Source
AI summary
The present document describes systems and methods that authorize client resources such as computers, servers, computing appliances, and virtual machines to access online services provided by an online service provider. To authorize a client resource, a client submits a registration request on behalf of the client resource to an authorization service provided by the service provider. The authorization service returns an activation code to the client. The activation code may expire after an amount of time, or upon first use. The client provides the activation code to an agent running on the client resource. The agent establishes communication with the authorization service, and upon providing the activation code to the authorization service, receives an authorization token that can be used by the client resource to access online services in accordance with security roles or permissions specified with the registration request.


