Cloud Access Policy Keys for Secure Third-Party Resource Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cloud computing platforms face challenges in securely managing third-party access to computing resources across multiple cloud environments, particularly in multi-cloud setups, due to issues with credential sharing, ownership, and scalability, which can lead to security vulnerabilities and operational inefficiencies.

Innovation Solution

A system and method for providing third-party trusted access by generating an access control policy key that defines permissions for a computing resource management tool, allowing it to access cloud resources securely and scalably, with automated credential management and correlation of resources across different cloud platforms.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If credential sharing is used to enable third-party access to cloud resources, then access capability is improved, but security is worsened

Engineering Contradiction:
Improveaccess capabilityVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments credentials into resource-specific access tokens with granular permissions, where each credential is limited to specific cloud resources and operations rather than providing broad access. This allows third-party tools to access only the minimum necessary resources, improving security while maintaining operational capability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary credential management service that acts as a broker between cloud providers and third-party tools. This intermediary issues and manages temporary credentials, validates access requests, and enforces security policies, thereby enabling secure access without direct credential sharing between end parties.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If access credentials are shared across multiple cloud environments, then multi-cloud access is improved, but credential management complexity is worsened

Engineering Contradiction:
Improvemulti-cloud accessVSAvoidcredential management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent creates a universal credential management system that works across multiple cloud providers through standardized interfaces and protocols. The same credential management service can issue credentials for different cloud environments (AWS, Azure, GCP, etc.), eliminating the need for separate credential management systems for each cloud provider and reducing overall complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent uses credential templates and profiles that can be copied and adapted across different cloud environments. Instead of manually configuring credentials for each cloud provider, administrators can create a template once and replicate it across multiple clouds with minimal modification, significantly reducing management complexity while maintaining multi-cloud versatility.

Inventive Principle:
Principle #26Copying

3Productivity

If third-party tools are granted access to cloud resources, then operational efficiency is improved, but security vulnerability is worsened

Engineering Contradiction:
Improveoperational efficiencyVSAvoidsecurity vulnerability
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent implements dynamic credentials with automatic expiration and rotation capabilities. Access credentials are temporary and automatically revoked after a set period or upon completion of specific tasks, reducing the window of vulnerability. The system dynamically adjusts credential lifecycles based on operational needs, maintaining efficiency while minimizing security exposure.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent incorporates continuous monitoring and feedback mechanisms that track credential usage in real-time. The system detects anomalous access patterns, validates operational necessity, and can automatically revoke credentials when misuse is detected. This feedback loop maintains operational efficiency by allowing legitimate access while rapidly responding to and mitigating security threats.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS20250245069A1Systems and methods for third-party trusted access in a computing cloud platform
Publication Date: 2025.07.31 DELL PROD LP
  • US20250245069A1 patent drawing
  • US20250245069A1 patent drawing
  • US20250245069A1 patent drawing

AI summary

Systems and methods for third-party trusted access are provided. According to one embodiment, an Information Handling System (IHS) includes a cloud computing platform with multiple computing resources, and computer-executable instructions to receive, from a customer, a request to grant to a computing resource management tool limited access to at least a portion of the computing resources, the computing resource management tool managed by a vendor of the computing resources, and generate an access control policy key in response to the request. The key includes one or more policies associated with how the computing resource management tool is allowed to access the portion of computing resources. The instructions also provides the key to the computing resource management tool, and accesses, by the computing resource management tool, the portion of computing resources according to the policies included in the key.