Cloud Authentication Plug-in Model for Data Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In cloud computing environments, businesses face challenges in ensuring the integrity, confidentiality, and privacy of their critical information due to the risk of exposure when deploying applications and data in shared resources, as they lose control over their data and are vulnerable to administrative actions by cloud service providers.

Innovation Solution

An authentication and authorization plug-in model is introduced, allowing customers to use their own security modules within the cloud environment, with a third-party notary service acting as an intermediary to ensure that resources and data are only released under specific conditions, such as joint approval or data erasure, preventing unilateral access by the cloud administrator.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If cloud service providers use centralized administrative control to manage shared computing resources, then resource allocation efficiency is improved, but data security and customer control are worsened

Engineering Contradiction:
Improveresource allocation efficiencyVSAvoiddata security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent segments control authority by introducing customer-managed security modules that operate independently within the cloud environment. These modules partition the centralized administrative control into distributed security enforcement points, allowing resource allocation efficiency to be maintained while data security is strengthened through decentralized authentication and authorization.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces customer security modules as intermediary components between the cloud service provider's infrastructure and customer data. These modules act as mediators that enforce security policies without preventing efficient resource management, thus resolving the contradiction between centralized control efficiency and data security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If cloud service providers allow administrators to access and manage allocated resources, then operational flexibility is improved, but unauthorized access risk is worsened

Engineering Contradiction:
Improveoperational flexibilityVSAvoidunauthorized access risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

Customer security modules serve as intermediary authentication and authorization layers that cloud administrators cannot bypass. These modules verify all access requests independently, maintaining operational flexibility for legitimate operations while blocking unauthorized access attempts, thus resolving the contradiction between administrative flexibility and security risk.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Loss of energy

If enterprises deploy applications in cloud shared environments, then IT cost reduction is improved, but information exposure risk is worsened

Engineering Contradiction:
ImproveIT costVSAvoidinformation exposure risk
Core Design Contradiction:
Loss of energyVSLoss of information

Solution Approach 1:

The patent extracts security control functionality from the shared cloud environment and embeds it within customer-managed modules. This extraction allows enterprises to maintain full security control over their information while utilizing the cost-effective shared infrastructure, thus resolving the contradiction between IT cost reduction and information exposure risk.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS9288214B2Authentication and authorization methods for cloud computing platform security
Publication Date: 2016.03.15 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US9288214B2 patent drawing
  • US9288214B2 patent drawing
  • US9288214B2 patent drawing

AI summary

An authentication and authorization plug-in model for a cloud computing environment enables cloud customers to retain control over their enterprise information when their applications are deployed in the cloud. The cloud service provider provides a pluggable interface for customer security modules. When a customer deploys an application, the cloud environment administrator allocates a resource group for the customer's application and data. The customer registers its own authentication and authorization security module with the cloud security service, and that security module is then used to control what persons or entities can access information associated with the deployed application. To further balance the rights of the various parties, a third party notary service protects the privacy and the access right of the customer when its application and information are deployed in the cloud.