Cloud Policy Distribution via Embedded Attribute Metadata

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Modern cloud computing systems face scalability and security challenges as they grow in size and complexity, with increased risks of breaches and performance issues due to separate resource storage and authorization services, leading to potential bottlenecks and increased costs.

Innovation Solution

A secure policy distribution method is implemented in cloud systems, using attribute-based encryption and metadata structures to define access policies, allowing authorization functions to be processed efficiently across cloud resources, with policies stored as encrypted metadata, enabling secure and scalable access management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If separate resource storage and authorization services are used in cloud systems, then security control is improved, but system complexity and operational bottlenecks increase

Engineering Contradiction:
Improvesecurity controlVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines resource storage and authorization services into an integrated system where authorization metadata is stored directly with resource data. This eliminates the need for separate remote access control systems while maintaining security control, thereby reducing system complexity and operational bottlenecks.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system enables self-service authorization by embedding authorization metadata within resource storage. Each resource contains its own authorization information, allowing the system to autonomously determine access permissions without requiring external authorization services, thus reducing complexity while maintaining security.

Inventive Principle:
Principle #25Self-service

2Reliability

If remote access control systems are used for cloud resources, then security management is improved, but operational costs and performance bottlenecks increase

Engineering Contradiction:
Improvesecurity managementVSAvoidoperational costs
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent extracts the authorization management function from remote access control systems and embeds it directly into the cloud storage infrastructure. By storing authorization metadata locally with resource data, the system eliminates dependencies on remote authorization services, reducing operational costs and removing performance bottlenecks while maintaining security management capabilities.

Inventive Principle:
Principle #2Taking out (Extraction)

3Productivity

If cloud systems scale up to handle more users and services, then service capacity is improved, but security breach risks and performance issues increase

Engineering Contradiction:
Improveservice capacityVSAvoidsecurity breach risks
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent segments authorization metadata into discrete attributes that are embedded with individual resource data. This granular segmentation allows the system to scale efficiently by processing only relevant authorization attributes for each access request, rather than managing centralized authorization data, thereby maintaining security breach risks at acceptable levels while increasing service capacity.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS20230179634A1Secure policy distribution in a cloud environment
Publication Date: 2023.06.08 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US20230179634A1 patent drawing
  • US20230179634A1 patent drawing
  • US20230179634A1 patent drawing

AI summary

A computer-implemented method for secure policy distribution to a cloud system. The method includes defining an access policy for a set of resources on a cloud computing system, where the access policy includes rules to allow access to the set of resources. The method further includes creating, based on the access policy, an activation function and attribute metadata in the cloud computing system, where the attribute metadata includes a set of access attributes for each resource of the set of resources. The method also includes, receiving a request to access a first resource of the set of resources, where the request includes a set of credentials. The method includes comparing, by the activation function, the set of credentials to the set of access attributes. The method further includes processing, based on the comparing, the request the access the first resource.