Authorization Service Handshake for Cloud Resource Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Managing access to online services for client resources such as servers and virtual machines is complex, as they often require different access levels and multiple credentials, and updating credentials across resources is cumbersome.

Innovation Solution

An authorization service that issues a one-time-use activation code to client resources, allowing them to register and obtain an authorization token for accessing online services, with an authorization agent installed to manage and refresh tokens, while detecting and differentiating cloned resources.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If client credentials are distributed to client resources for access to online services, then client resources can access online services, but managing and updating credentials across multiple resources becomes complex and troublesome

Engineering Contradiction:
Improvecredential managementVSAvoidauthorization system
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent introduces an authorization service as an intermediary between the online service and client resources. This service manages credentials centrally and issues authorization tokens to client resources, eliminating the need to distribute and manage client credentials across multiple resources. The authorization service acts as a mediator that handles authentication and authorization, simplifying credential management while maintaining security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates authorization tokens that are copies or representations of client credentials. Instead of distributing actual client credentials to multiple resources, the system generates token copies that grant access rights. These tokens can be safely distributed and revoked without affecting the original credentials, making credential management much easier.

Inventive Principle:
Principle #26Copying

2Adaptability or versatility

If multiple sets of client credentials are provided for accessing multiple online services, then client resources can access multiple services, but the complexity of managing multiple credential sets increases

Engineering Contradiction:
Improveservice access capabilityVSAvoidcredential management
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The authorization service provides a universal authorization mechanism that works across multiple online services. Instead of requiring separate credential sets for each service, the system issues authorization tokens that can be used to access multiple services. This multi-functional approach allows client resources to access various online services while managing a single set of authorization tokens, significantly reducing management complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If client credentials are updated, then security is improved, but all client resources using those credentials must be updated, which is cumbersome

Engineering Contradiction:
ImprovesecurityVSAvoidcredential update time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system uses authorization tokens as copies of credential authority. When credentials need to be updated or revoked, the authorization service can simply invalidate the corresponding authorization tokens without affecting the original client credentials. This allows rapid security updates by regenerating or revoking tokens, saving significant time compared to updating credentials across all client resources.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The authorization service implements a mechanism where old or compromised authorization tokens can be discarded (revoked) and new tokens can be issued. This allows the system to quickly respond to security incidents by invalidating specific tokens without needing to update all client resources, enabling rapid credential rotation and recovery.

Inventive Principle:
Principle #34Discarding and recovering

Data Source

PatentUS10440151B2Service authorization handshake
Publication Date: 2019.10.08 AMAZON TECH INC
  • US10440151B2 patent drawing
  • US10440151B2 patent drawing
  • US10440151B2 patent drawing

AI summary

The present document describes systems and methods that authorize client resources such as computers, servers, computing appliances, and virtual machines to access online services provided by an online service provider. To authorize a client resource, a client submits a registration request on behalf of the client resource to an authorization service provided by the service provider. The authorization service returns an activation code to the client. The activation code may expire after an amount of time, or upon first use. The client provides the activation code to an agent running on the client resource. The agent establishes communication with the authorization service, and upon providing the activation code to the authorization service, receives an authorization token that can be used by the client resource to access online services in accordance with security roles or permissions specified with the registration request.