Cloud Authentication Plug-in Model for Data Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In cloud computing environments, businesses face challenges in ensuring the integrity, confidentiality, and privacy of their critical information due to the risk of exposure when deploying applications and data in shared resources, as they lose control over their data and are vulnerable to administrative actions by cloud service providers.
Innovation Solution
An authentication and authorization plug-in model is introduced, allowing customers to use their own security modules within the cloud environment, with a third-party notary service acting as an intermediary to ensure that resources and data are only released under specific conditions, such as joint approval or data erasure, preventing unilateral access by the cloud administrator.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If cloud service providers use centralized administrative control to manage shared computing resources, then resource allocation efficiency is improved, but data security and customer control are worsened
Solution Approach 1:
The patent segments control authority by introducing customer-managed security modules that operate independently within the cloud environment. These modules partition the centralized administrative control into distributed security enforcement points, allowing resource allocation efficiency to be maintained while data security is strengthened through decentralized authentication and authorization.
Solution Approach 2:
The patent introduces customer security modules as intermediary components between the cloud service provider's infrastructure and customer data. These modules act as mediators that enforce security policies without preventing efficient resource management, thus resolving the contradiction between centralized control efficiency and data security.
2Adaptability or versatility
If cloud service providers allow administrators to access and manage allocated resources, then operational flexibility is improved, but unauthorized access risk is worsened
Solution Approach 1:
Customer security modules serve as intermediary authentication and authorization layers that cloud administrators cannot bypass. These modules verify all access requests independently, maintaining operational flexibility for legitimate operations while blocking unauthorized access attempts, thus resolving the contradiction between administrative flexibility and security risk.
3Loss of energy
If enterprises deploy applications in cloud shared environments, then IT cost reduction is improved, but information exposure risk is worsened
Solution Approach 1:
The patent extracts security control functionality from the shared cloud environment and embeds it within customer-managed modules. This extraction allows enterprises to maintain full security control over their information while utilizing the cost-effective shared infrastructure, thus resolving the contradiction between IT cost reduction and information exposure risk.
Data Source
AI summary
An authentication and authorization plug-in model for a cloud computing environment enables cloud customers to retain control over their enterprise information when their applications are deployed in the cloud. The cloud service provider provides a pluggable interface for customer security modules. When a customer deploys an application, the cloud environment administrator allocates a resource group for the customer's application and data. The customer registers its own authentication and authorization security module with the cloud security service, and that security module is then used to control what persons or entities can access information associated with the deployed application. To further balance the rights of the various parties, a third party notary service protects the privacy and the access right of the customer when its application and information are deployed in the cloud.


