Cloud Authorization Manager for Personal Data Isolation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
End-users are concerned about the security and privacy of their personal data in the cloud due to misuse, hacking, and mass surveillance, leading to a loss of trust and perception of insecurity, with existing cloud providers lacking transparency in data processing.
Innovation Solution
A cloud-platform that implements an authorization protocol like OAuth to provide user control over personal data access, using multi-tenant database instances for secure storage and isolated access, with access tokens based on user-defined scopes, ensuring that users can grant and revoke access to their data securely.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If cloud providers store and process personal data centrally, then data accessibility and service functionality are improved, but security and privacy risks increase due to potential misuse, hacking, and mass surveillance
Solution Approach 1:
The patent implements data segmentation by creating separate database containers for different users, isolating personal data so that one user cannot access another user's data. This segmentation maintains data accessibility for authorized users while reducing security risks by limiting the impact of potential breaches to individual containers rather than exposing all data centrally.
Solution Approach 2:
The patent introduces an authorization manager as an intermediary component between applications and personal data. This mediator handles authentication and authorization decisions, controlling access tokens and scope definitions. The intermediary layer enables secure data access while preventing unauthorized access, hacking, and misuse by centralizing security control logic.
2Reliability
If cloud providers offer transparent data processing services, then user trust and control are improved, but system complexity increases due to additional authorization protocols and access control mechanisms
Solution Approach 1:
The patent implements a universal authorization manager that handles multiple functions: authentication, authorization, access token management, and scope definition control. This multi-functional approach improves user trust through transparent data processing while managing complexity by consolidating multiple security functions into a single manageable component rather than distributing them across multiple separate systems.
3Adaptability or versatility
If applications are granted broad access to personal data, then application functionality is improved, but security risks increase due to credential sharing and misuse
Solution Approach 1:
The patent applies local quality by defining specific scopes that limit access to particular types of data or operations based on the application's needs. Instead of granting broad access, each application receives targeted permissions (e.g., read-only access to specific data types), reducing the risk of credential sharing and misuse while maintaining necessary functionality for each specific application.
Solution Approach 2:
The patent implements partial action by granting applications only the minimum necessary access rights through scope definitions, rather than full access. This partial authorization approach enables applications to function for their specific purposes while limiting their ability to access or misuse data beyond what is strictly necessary, thereby reducing security risks.
Data Source
AI summary
Implementations of the present disclosure include methods, systems, and computer-readable storage mediums for receiving, by an authorization manager of a cloud-platform, a request from an application, the request indicating a request to access personal user data stored in a database system of the cloud-platform, determining, by the authorization manager and based on user input from a user, that access to the personal user data is to be granted, and in response: providing, by the authorization manager, an access token to the application, receiving an access request from the application, the access request including the access token, and selectively providing the personal user data from a database container of the database system based on the access token, the database container being specific to the user.


