Cloud Infrastructure Realm Access Security Through Cross-Domain Approval

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cloud computing environments face challenges in managing access control across multiple identity domains, particularly in ensuring secure access to sensitive information while maintaining data privacy and compliance with regulatory requirements.

Innovation Solution

Implementing approval workflows that involve cross-domain approvals, where access requests are managed through sequences of approvals across different identity domains, ensuring that sensitive information remains within its domain and relying on authentication and final approvals from the requester's domain.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If access requests are transmitted across multiple identity domains for approval, then security control and compliance are improved, but the complexity of access management increases

Engineering Contradiction:
Improvesecurity controlVSAvoidaccess management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments the access approval process into distinct phases: initial approval from the requester's identity domain, then transmission of anonymized credentials to target domain for final approval. This segmentation allows each domain to perform its specific approval function without exposing sensitive information across domains, thereby improving security control while managing complexity through clear process division.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces anonymized credentials as an intermediary mechanism between identity domains. Instead of transmitting sensitive user information directly across domains, the system uses anonymized credentials that preserve authentication capability while removing personally identifiable information. This intermediary approach enhances security control by preventing sensitive data exposure while maintaining the necessary approval workflow.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If sensitive information is transmitted across identity domains for verification, then access control accuracy is improved, but data privacy and security are compromised

Engineering Contradiction:
Improveaccess control accuracyVSAvoiddata privacy risk
Core Design Contradiction:
Measurement precisionVSObject-affected harmful factors

Solution Approach 1:

The system extracts personally identifiable information from the access request before transmitting it to the target identity domain. Only anonymized credentials are transmitted across domains, which maintain authentication capability but remove sensitive user data. This extraction approach ensures access control accuracy is maintained through proper verification while eliminating data privacy risks associated with transmitting sensitive information across domains.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent employs anonymized credentials as temporary, disposable objects for cross-domain verification. These credentials serve their purpose of enabling access control verification but contain no persistent sensitive information that could be compromised. The use of temporary anonymized tokens rather than permanent sensitive data achieves accurate access control while preventing long-term data privacy vulnerabilities.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Data Source

PatentUS20250286888A1System And Method For Managing Security For A Cloud Infrastructure Realm Using Cross-Domain Approval
Publication Date: 2025.09.11 ORACLE INT CORP
  • US20250286888A1 patent drawing
  • US20250286888A1 patent drawing
  • US20250286888A1 patent drawing

AI summary

Techniques for providing dedicated or private label cloud (PLC) environments for use by tenants of a cloud infrastructure environment in accessing software products, services, or other offerings associated with the environment are disclosed. An operator, authenticated with respect to a provider identity domain, makes a request to access a resource associated with an operator tenancy without being associated with the operator identity domain. A cross-domain approval process is executed to determine whether or not to provide access to the operator.