Authentication Module for Cloud Access Control Flexibility

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cloud computing solutions lack flexibility in access control mechanisms, as they employ a single predefined access control model for all client entities, which may not be suitable for varying customer needs, and pose security concerns due to reliance on a shared infrastructure vulnerable to attacks.

Innovation Solution

A method and system that implement a secure access control mechanism using an authentication and authorization module located between the user's terminal and the cloud computing platform, allowing for personalized access control models and policies for each client entity, enabling dynamic updates and real-time adaptation to access control requirements.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a single predefined access control model is used for all client entities, then the system is simpler to manage, but it lacks flexibility to meet varying customer needs

Engineering Contradiction:
Improveaccess control flexibilityVSAvoidaccess control system complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the access control system by introducing an authentication and authorization module that operates independently between the terminal and cloud platform. This module allows different access control models to be applied to different client entities, enabling customized access policies for each entity while maintaining system manageability through modular architecture.

Inventive Principle:
Principle #1Segmentation

2Reliability

If access control is based on a shared cloud infrastructure, then resource pooling and scalability are improved, but security concerns increase due to vulnerability to attacks

Engineering Contradiction:
Improveaccess securityVSAvoidsecurity vulnerabilities
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an authentication and authorization module as an intermediary component between the terminal and the cloud computing platform. This intermediary validates user credentials, verifies authorization tokens, and controls access to cloud resources, thereby enhancing security without compromising the shared infrastructure's scalability and resource pooling capabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If the cloud service provider manages all authentication and authorization, then the platform has full control, but the burden and complexity on the provider increases

Engineering Contradiction:
Improveaccess control managementVSAvoidplatform management complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent implements a self-service mechanism where each client entity can define and manage their own access control policies through the authentication and authorization module. The system automatically validates user credentials and generates authorization tokens without requiring manual intervention from the cloud service provider, thereby reducing the provider's management burden while maintaining ease of access control operation.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP2819052B1Method and server for processing a request for a terminal to access a computer resource
Publication Date: 2018.08.01 ORANGE SA
  • EP2819052B1 patent drawingFigure 1
  • EP2819052B1 patent drawingFigure 2~3
  • EP2819052B1 patent drawingFigure 4A~4B

AI summary

The invention relates to a method for processing an access request from a terminal (2) of a user (U) to a resource (R1) made available to a client entity (E) by a platform (3) of a cloud computing service provider, this method being intended to be implemented by an authentication and authorization module (5) of a server (4) dedicated to the client entity, and comprising, following receipt of the access request: - authentication of the user using initial user authentication parameters with the server; - verification that the user is authorized to access the resource by applying to the user and the resource an access control model and an access control policy corresponding to this model obtained for the client entity;- if the user is authorized to access the resource, sending to the platform a request derived from the access request based on secondary authentication parameters of the client entity with the platform; - otherwise, rejecting the access request.