Cloud Infrastructure Access Control Mediator for Regulatory Compliance
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Regulated customers, such as banks and medical providers, face challenges in cloud computing environments due to the need for complete control over their systems to comply with legal and contractual requirements, which conflicts with the conventional cloud computing model where cloud providers have unfettered access and control.
Innovation Solution
Implementing a customer-controlled access mechanism that allows cloud customers to manage access to cloud infrastructure resources by creating access control profiles and policies, enabling granular control over operator access, ensuring compliance with regulatory requirements through approval processes and audit logging.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If cloud provider's administrative staff have full and unfettered access to cloud resources, then ease of operation and administrative efficiency is improved, but customer control and compliance capability deteriorates
Solution Approach 1:
The patent introduces an intermediary access control mechanism between the cloud provider's administrative staff and the cloud resources. This mediator system requires customer approval for operator access requests, logging and monitoring all access attempts. The intermediary layer maintains ease of operation for administrators while ensuring customer control and compliance through structured authorization protocols.
Solution Approach 2:
The patent implements feedback mechanisms through audit logging and monitoring systems that track all operator access requests and actions. The system provides feedback to customers about access attempts, allowing them to review and control operator access. This feedback loop enables customers to maintain control and compliance while operators can still perform administrative functions with proper authorization.
2Productivity
If cloud provider's administrative staff have complete control over cloud infrastructure, then productivity and administrative efficiency is improved, but customer compliance and audit capability deteriorates
Solution Approach 1:
The patent implements comprehensive feedback through audit logging that captures all operator access requests, approvals, and actions taken on cloud resources. This feedback mechanism ensures that no administrative action occurs without being recorded and made available for customer review, maintaining both productivity and audit capability.
Solution Approach 2:
The access control system acts as an intermediary that records and monitors all interactions between operators and cloud resources. This mediator ensures complete audit trails are maintained while allowing operators to perform administrative functions efficiently with proper authorization.
3Reliability
If customer has complete control over system actions, then compliance and regulatory requirement is improved, but ease of operation and administrative efficiency deteriorates
Solution Approach 1:
The patent introduces an intermediary access control system that mediates between customer compliance requirements and operator operational efficiency. The system provides structured approval processes and audit logging that satisfy compliance requirements while maintaining ease of operation through automated authorization workflows.
Solution Approach 2:
The patent implements preliminary action through pre-approval configurations where customers can define access policies and authorization rules in advance. This preliminary setup enables operators to perform administrative functions efficiently while ensuring compliance, as the approval frameworks are established beforehand rather than requiring ad-hoc customer intervention for each action.
Data Source
AI summary
Disclosed is an improved approach to implement a mechanism to provide customer control over access to cloud infrastructure by the cloud provider's operator employees. This mechanism allow customer controlled access to any cloud infrastructure that belongs to or is otherwise allocated to the customer.


