Cloud Authorization Manager for Personal Data Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

End-users are concerned about the security and privacy of their personal data in the cloud due to misuse, hacking, and mass surveillance, leading to a loss of trust and perception of insecurity, with existing cloud providers lacking transparency in data processing.

Innovation Solution

A cloud-platform that implements an authorization protocol like OAuth to provide user control over personal data access, using multi-tenant database instances for secure storage and isolated access, with access tokens based on user-defined scopes, ensuring that users can grant and revoke access to their data securely.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If cloud providers store and process personal data centrally, then data accessibility and service functionality are improved, but security and privacy risks increase due to potential misuse, hacking, and mass surveillance

Engineering Contradiction:
Improvedata accessibilityVSAvoidsecurity and privacy risks
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements data segmentation by creating separate database containers for different users, isolating personal data so that one user cannot access another user's data. This segmentation maintains data accessibility for authorized users while reducing security risks by limiting the impact of potential breaches to individual containers rather than exposing all data centrally.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an authorization manager as an intermediary component between applications and personal data. This mediator handles authentication and authorization decisions, controlling access tokens and scope definitions. The intermediary layer enables secure data access while preventing unauthorized access, hacking, and misuse by centralizing security control logic.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If cloud providers offer transparent data processing services, then user trust and control are improved, but system complexity increases due to additional authorization protocols and access control mechanisms

Engineering Contradiction:
Improveuser trustVSAvoidauthorization system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal authorization manager that handles multiple functions: authentication, authorization, access token management, and scope definition control. This multi-functional approach improves user trust through transparent data processing while managing complexity by consolidating multiple security functions into a single manageable component rather than distributing them across multiple separate systems.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Adaptability or versatility

If applications are granted broad access to personal data, then application functionality is improved, but security risks increase due to credential sharing and misuse

Engineering Contradiction:
Improveapplication functionalityVSAvoidcredential sharing and misuse
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies local quality by defining specific scopes that limit access to particular types of data or operations based on the application's needs. Instead of granting broad access, each application receives targeted permissions (e.g., read-only access to specific data types), reducing the risk of credential sharing and misuse while maintaining necessary functionality for each specific application.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent implements partial action by granting applications only the minimum necessary access rights through scope definitions, rather than full access. This partial authorization approach enables applications to function for their specific purposes while limiting their ability to access or misuse data beyond what is strictly necessary, thereby reducing security risks.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS10162982B2End user control of personal data in the cloud
Publication Date: 2018.12.25 SAP SE
  • US10162982B2 patent drawing
  • US10162982B2 patent drawing
  • US10162982B2 patent drawing

AI summary

Implementations of the present disclosure include methods, systems, and computer-readable storage mediums for receiving, by an authorization manager of a cloud-platform, a request from an application, the request indicating a request to access personal user data stored in a database system of the cloud-platform, determining, by the authorization manager and based on user input from a user, that access to the personal user data is to be granted, and in response: providing, by the authorization manager, an access token to the application, receiving an access request from the application, the access request including the access token, and selectively providing the personal user data from a database container of the database system based on the access token, the database container being specific to the user.