Cloud Infrastructure Realm Access Security Through Cross-Domain Approval
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing cloud computing environments face challenges in managing access control across multiple identity domains, particularly in ensuring secure access to sensitive information while maintaining data privacy and compliance with regulatory requirements.
Innovation Solution
Implementing approval workflows that involve cross-domain approvals, where access requests are managed through sequences of approvals across different identity domains, ensuring that sensitive information remains within its domain and relying on authentication and final approvals from the requester's domain.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If access requests are transmitted across multiple identity domains for approval, then security control and compliance are improved, but the complexity of access management increases
Solution Approach 1:
The system segments the access approval process into distinct phases: initial approval from the requester's identity domain, then transmission of anonymized credentials to target domain for final approval. This segmentation allows each domain to perform its specific approval function without exposing sensitive information across domains, thereby improving security control while managing complexity through clear process division.
Solution Approach 2:
The patent introduces anonymized credentials as an intermediary mechanism between identity domains. Instead of transmitting sensitive user information directly across domains, the system uses anonymized credentials that preserve authentication capability while removing personally identifiable information. This intermediary approach enhances security control by preventing sensitive data exposure while maintaining the necessary approval workflow.
2Measurement precision
If sensitive information is transmitted across identity domains for verification, then access control accuracy is improved, but data privacy and security are compromised
Solution Approach 1:
The system extracts personally identifiable information from the access request before transmitting it to the target identity domain. Only anonymized credentials are transmitted across domains, which maintain authentication capability but remove sensitive user data. This extraction approach ensures access control accuracy is maintained through proper verification while eliminating data privacy risks associated with transmitting sensitive information across domains.
Solution Approach 2:
The patent employs anonymized credentials as temporary, disposable objects for cross-domain verification. These credentials serve their purpose of enabling access control verification but contain no persistent sensitive information that could be compromised. The use of temporary anonymized tokens rather than permanent sensitive data achieves accurate access control while preventing long-term data privacy vulnerabilities.
Data Source
AI summary
Techniques for providing dedicated or private label cloud (PLC) environments for use by tenants of a cloud infrastructure environment in accessing software products, services, or other offerings associated with the environment are disclosed. An operator, authenticated with respect to a provider identity domain, makes a request to access a resource associated with an operator tenancy without being associated with the operator identity domain. A cross-domain approval process is executed to determine whether or not to provide access to the operator.


