Dynamic Cloud Access Control via Dual Model Synchronization
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current access control mechanisms, such as RBAC and OrBAC, are insufficient for managing access to cloud computing systems due to their static nature, which cannot adapt to the dynamic allocation of resources and organizational changes in cloud environments.
Innovation Solution
A method and device that utilize two models: a first model describing computer resources and networks, and a second hierarchical model representing the entity's organization, with algorithms for resource allocation, to dynamically manage access by reflecting the current state of resources and entity organization, ensuring compatibility and scalability.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If static access control models (RBAC/OrBAC) are used, then access control is simple to implement, but adaptability to dynamic resource allocation and organizational changes is insufficient
Solution Approach 1:
The patent transforms static access control models into dynamic systems by introducing continuous updating mechanisms. The access control system now dynamically adjusts to resource allocation changes and organizational restructuring through automated model updates, enabling adaptability while managing complexity through systematic approaches.
Solution Approach 2:
The patent implements feedback mechanisms where the system continuously monitors resource allocation and organizational structure changes, then updates access control models accordingly. This closed-loop approach ensures the system adapts to dynamic conditions while maintaining control through structured feedback processing.
2Adaptability or versatility
If dynamic access control is implemented to reflect current state, then adaptability improves, but system complexity and computational overhead increase
Solution Approach 1:
The patent applies preliminary action by pre-defining update triggers and automated procedures. When resource allocation or organizational structure changes occur, the system automatically initiates model updating processes in advance, ensuring the access control system reflects current states without requiring complex real-time computation during access decisions.
Solution Approach 2:
The patent segments the access control system into distinct functional components: resource modeling, organization modeling, update mechanisms, and access decisioning. This segmentation allows each component to handle complexity independently, with models updated separately from access control decisions, reducing overall system complexity.
3Reliability
If access control checks current resource allocation, then security and compatibility are enhanced, but processing time for access requests increases
Solution Approach 1:
The patent applies preliminary action by updating access control models in advance of access requests. By maintaining current models of resource allocation and organizational structure, the system can quickly verify compatibility without performing complex real-time calculations during access decisioning, thus enhancing security while reducing processing time.
Solution Approach 2:
The patent uses copying by creating simplified representations (models) of resource allocation and organizational structure that capture essential information for access control decisions. These models serve as copies that can be rapidly queried during access requests without requiring complex real-time analysis of the actual resource state.
Data Source
Figure 1~4
Figure 3A~3B
Figure 5A~5B
AI summary
The method according to the invention comprises: ¾ the updating (E30, E50), of a first model describing the set of computer resources and networks, and of a second multilevel hierarchical model describing the entity, each level comprising at least one element grouping together one or more users of the entity and being associated with an algorithm for allocating at least part of the set of resources, the union of the elements of a hierarchical level grouping together the plurality of users, so that the first and the second model reflect a current state of the set of resources and of the entity; ¾ on receipt (F10) of a request from a user to access a resource, designated in the request, of the set of resources, the identification (F50) of the resources intended for the user from among the set of resources by applying the algorithms of the second model to the current state of the set of resources reflected by the first model, the verification (F60) of the compatibility of the resources identified with the resource designated in the request, and the rejection (F30) of the request in the event of incompatibility.