Cloud Resource Access Using Consent Workflows and Policy Checks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cloud environments lack effective mechanisms for managing access to cloud resources while ensuring user consent and adherence to access policies, leading to potential security and privacy issues.

Innovation Solution

Implementing a consent-driven access management system that requires user approval through consent workflows and adherence to separate access policies before granting access to cloud resources, using consent tokens to condition access permissions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If the CSP retains full access control over cloud resources to ensure sufficient resources for customer needs, then resource availability and service delivery are improved, but security and privacy control for customers deteriorate

Engineering Contradiction:
Improveresource availabilityVSAvoidsecurity control
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent segments access control into two distinct layers: (1) CSP operational access for resource provisioning and management, and (2) customer-controlled access for data and application resources. This segmentation allows the CSP to maintain full access for service delivery while customers retain control over their specific resources through consent workflows and policies.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary access control mechanism consisting of consent workflows, access policies, and consent tokens. These intermediaries mediate between the CSP's need for full access and the customer's need for security control, enabling conditional access where the CSP can access resources only when consent is granted through defined workflows.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If traditional access control mechanisms are used to manage cloud resource access, then ease of operation is improved, but security and privacy protection deteriorate

Engineering Contradiction:
Improveaccess managementVSAvoidsecurity risks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent implements preliminary action by requiring consent workflows to be defined and access policies to be established before any resource access occurs. Consent tokens are obtained in advance, and access is granted only when pre-defined policies are satisfied, preventing unauthorized access before it can occur.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent incorporates feedback mechanisms where access decisions are continuously evaluated against defined policies. The system provides feedback loops that monitor access requests, validate consent tokens, and enforce policy constraints, creating a dynamic security system that adapts to access attempts in real-time.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS12585446B2Consent-driven access management for cloud resources
Publication Date: 2026.03.24 ORACLE INT CORP
  • US12585446B2 patent drawing
  • US12585446B2 patent drawing
  • US12585446B2 patent drawing

AI summary

Techniques for consent-driven access management include: receiving, from a requestor, a request for consent for an actor to access a target set of resources in a cloud environment; identifying a consent workflow that specifies a name and/or an attribute of a set of one or more users from which to obtain respective approvals of the consent request; traversing the consent workflow to obtain the respective approvals from the set of one or more users; determining that one or more access policies, separate from the consent workflow, permit the actor to access the target set of resources; where access by the actor to the target set of resources is conditioned on both (a) obtaining the respective approvals from the set of one or more users and (b) determining that the one or more access policies, separate from the consent workflow, permit the actor to access the target set of resources.