Dynamic Cloud Access Control via Dual Model Synchronization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current access control mechanisms, such as RBAC and OrBAC, are insufficient for managing access to cloud computing systems due to their static nature, which cannot adapt to the dynamic allocation of resources and organizational changes in cloud environments.

Innovation Solution

A method and device that utilize two models: a first model describing computer resources and networks, and a second hierarchical model representing the entity's organization, with algorithms for resource allocation, to dynamically manage access by reflecting the current state of resources and entity organization, ensuring compatibility and scalability.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If static access control models (RBAC/OrBAC) are used, then access control is simple to implement, but adaptability to dynamic resource allocation and organizational changes is insufficient

Engineering Contradiction:
Improveadaptability to dynamic resource allocationVSAvoidaccess control system complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent transforms static access control models into dynamic systems by introducing continuous updating mechanisms. The access control system now dynamically adjusts to resource allocation changes and organizational restructuring through automated model updates, enabling adaptability while managing complexity through systematic approaches.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent implements feedback mechanisms where the system continuously monitors resource allocation and organizational structure changes, then updates access control models accordingly. This closed-loop approach ensures the system adapts to dynamic conditions while maintaining control through structured feedback processing.

Inventive Principle:
Principle #23Feedback

2Adaptability or versatility

If dynamic access control is implemented to reflect current state, then adaptability improves, but system complexity and computational overhead increase

Engineering Contradiction:
Improvereflect current state of resourcesVSAvoidmodel updating mechanism complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by pre-defining update triggers and automated procedures. When resource allocation or organizational structure changes occur, the system automatically initiates model updating processes in advance, ensuring the access control system reflects current states without requiring complex real-time computation during access decisions.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent segments the access control system into distinct functional components: resource modeling, organization modeling, update mechanisms, and access decisioning. This segmentation allows each component to handle complexity independently, with models updated separately from access control decisions, reducing overall system complexity.

Inventive Principle:
Principle #1Segmentation

3Reliability

If access control checks current resource allocation, then security and compatibility are enhanced, but processing time for access requests increases

Engineering Contradiction:
Improveaccess control securityVSAvoidaccess request processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies preliminary action by updating access control models in advance of access requests. By maintaining current models of resource allocation and organizational structure, the system can quickly verify compatibility without performing complex real-time calculations during access decisioning, thus enhancing security while reducing processing time.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses copying by creating simplified representations (models) of resource allocation and organizational structure that capture essential information for access control decisions. These models serve as copies that can be rapidly queried during access requests without requiring complex real-time analysis of the actual resource state.

Inventive Principle:
Principle #26Copying

Data Source

PatentEP2901279B1Device and method for managing access to a set of network resources made available in a cloud system
Publication Date: 2021.04.21 ORANGE SA
  • EP2901279B1 patent drawingFigure 1~4
  • EP2901279B1 patent drawingFigure 3A~3B
  • EP2901279B1 patent drawingFigure 5A~5B

AI summary

The method according to the invention comprises: ¾ the updating (E30, E50), of a first model describing the set of computer resources and networks, and of a second multilevel hierarchical model describing the entity, each level comprising at least one element grouping together one or more users of the entity and being associated with an algorithm for allocating at least part of the set of resources, the union of the elements of a hierarchical level grouping together the plurality of users, so that the first and the second model reflect a current state of the set of resources and of the entity; ¾ on receipt (F10) of a request from a user to access a resource, designated in the request, of the set of resources, the identification (F50) of the resources intended for the user from among the set of resources by applying the algorithms of the second model to the current state of the set of resources reflected by the first model, the verification (F60) of the compatibility of the resources identified with the resource designated in the request, and the rejection (F30) of the request in the event of incompatibility.