Cloud Certificate Associations for Reliable Cross-Product Authorization
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Customers of cloud service providers face issues with managing certificate-based authentication in integrated cloud services, leading to unauthorized access and service failures due to the neglect or inadvertent revocation of policies, resulting in the inability to verify identities and fulfill requests.
Innovation Solution
The implementation of association objects that connect cloud resources with certificates, allowing direct access without policy-based verification, thereby eliminating the need for customers to manage and maintain separate policies, and ensuring continuous identity verification even in the face of policy changes or revocations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If policy-based verification is used for certificate access, then access control can be managed, but the system becomes complex and prone to errors due to policy neglect or revocation
Solution Approach 1:
The patent extracts the policy verification step from the certificate access flow by introducing association objects that directly bind certificates to cloud resources. This eliminates the need for separate policy management while maintaining access control, resolving the contradiction between reliable access control and policy management complexity.
Solution Approach 2:
The patent merges the certificate binding and access control functions into a single association object. This integration eliminates the need for separate policies and reduces system complexity while maintaining reliable access control through the unified association mechanism.
2Reliability
If separate policies are used to manage certificate access, then access control is possible, but service failures occur due to policy neglect or inadvertent revocation
Solution Approach 1:
The patent removes the separate policy management layer by using association objects that inherently bind certificates to resources. This extraction eliminates the risk of policy neglect or inadvertent revocation while maintaining service continuity, directly addressing the contradiction between service reliability and ease of operation.
Solution Approach 2:
The association object system enables self-service certificate access where the binding relationship automatically enables access without requiring separate policy management. This self-service mechanism prevents service failures due to human error in policy management while maintaining ease of operation.
3Measurement precision
If certificate-based authentication is implemented, then identity verification is possible, but unauthorized access occurs when policies are not properly managed
Solution Approach 1:
The patent combines identity verification and access control into the association object structure. This merging ensures that only authorized resources can access certificates for identity verification, preventing unauthorized access while maintaining verification accuracy through the integrated design.
Solution Approach 2:
The association object acts as an intermediary between the certificate and the cloud resource, mediating access control. This intermediary mechanism ensures that identity verification accuracy is maintained while preventing unauthorized access through the controlled association relationship.
4Extent of automation
If manual policy management is required, then access control can be configured, but automated certificate renewal and revocation cannot be implemented
Solution Approach 1:
The association object system enables automated certificate lifecycle management where the binding relationship automatically handles renewal and revocation without manual intervention. This self-service automation increases automation extent while the modular association structure keeps system complexity manageable.
Solution Approach 2:
The association object is created in advance with the certificate binding, enabling automated renewal and revocation actions to be performed without manual policy reconfiguration. This preliminary setup facilitates automation while maintaining acceptable system complexity through the pre-established association structure.
Data Source
AI summary
Techniques described herein relate to authorization between integrated cloud products. An example includes receiving, by a computing device and from a first resource, a first request for permission to access a certificate to verify a requestor's identity. The computing device can transmit a second request to a second resource to authorize permitting access to the certificate. The computing device can receive a response from the second resource comprising an authorization to permit access to the certificate. The computing device can grant permission to the first resource to access the certificate, wherein the first resource is configured to verify the requestor's identity based on accessing the certificate. The computing device can receive a third request from the first resource to generate an association object between the first resource and the certificate. The computing device can generate the association object, wherein the association object associates the first resource and the certificate.


