Cloud Resource Access Using Consent Workflows and Policy Checks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing cloud environments lack effective mechanisms for managing access to cloud resources while ensuring user consent and adherence to access policies, leading to potential security and privacy issues.
Innovation Solution
Implementing a consent-driven access management system that requires user approval through consent workflows and adherence to separate access policies before granting access to cloud resources, using consent tokens to condition access permissions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If the CSP retains full access control over cloud resources to ensure sufficient resources for customer needs, then resource availability and service delivery are improved, but security and privacy control for customers deteriorate
Solution Approach 1:
The patent segments access control into two distinct layers: (1) CSP operational access for resource provisioning and management, and (2) customer-controlled access for data and application resources. This segmentation allows the CSP to maintain full access for service delivery while customers retain control over their specific resources through consent workflows and policies.
Solution Approach 2:
The patent introduces an intermediary access control mechanism consisting of consent workflows, access policies, and consent tokens. These intermediaries mediate between the CSP's need for full access and the customer's need for security control, enabling conditional access where the CSP can access resources only when consent is granted through defined workflows.
2Ease of operation
If traditional access control mechanisms are used to manage cloud resource access, then ease of operation is improved, but security and privacy protection deteriorate
Solution Approach 1:
The patent implements preliminary action by requiring consent workflows to be defined and access policies to be established before any resource access occurs. Consent tokens are obtained in advance, and access is granted only when pre-defined policies are satisfied, preventing unauthorized access before it can occur.
Solution Approach 2:
The patent incorporates feedback mechanisms where access decisions are continuously evaluated against defined policies. The system provides feedback loops that monitor access requests, validate consent tokens, and enforce policy constraints, creating a dynamic security system that adapts to access attempts in real-time.
Data Source
AI summary
Techniques for consent-driven access management include: receiving, from a requestor, a request for consent for an actor to access a target set of resources in a cloud environment; identifying a consent workflow that specifies a name and/or an attribute of a set of one or more users from which to obtain respective approvals of the consent request; traversing the consent workflow to obtain the respective approvals from the set of one or more users; determining that one or more access policies, separate from the consent workflow, permit the actor to access the target set of resources; where access by the actor to the target set of resources is conditioned on both (a) obtaining the respective approvals from the set of one or more users and (b) determining that the one or more access policies, separate from the consent workflow, permit the actor to access the target set of resources.


