Cloud Resource Protection via Token-Based Process Class Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional cloud computing methods require hardware virtualization, which imposes performance overhead and security risks, and fail to effectively manage access control based on process or application classes across a cloud infrastructure.
Innovation Solution
A cloud resource protection method that authenticates users and assigns them tokens indicating permissions, allowing processes to execute and access restricted data sets without further authentication, using a non-virtualized cloud infrastructure and associating processes or applications with classes for access control policies.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If hardware virtualization is used for cloud computing, then security control over virtual machines is improved, but performance overhead and CPU tax increase
Solution Approach 1:
The patent extracts the virtualization layer from the cloud infrastructure, eliminating hardware virtualization while retaining security controls through class-based access policies applied directly to processes and data on the underlying hardware platform
Solution Approach 2:
The patent segments access control into fine-grained classes that can be applied to specific processes and data sets, replacing the coarse-grained virtual machine isolation approach with more granular, process-level security boundaries
2Reliability
If hardware virtualization is implemented, then security benefits are achieved, but memory overhead and system complexity increase
Solution Approach 1:
The patent removes the virtualization infrastructure from the system architecture, eliminating the associated memory overhead and complexity while maintaining security through a simplified class-based access control model operating directly on the hardware platform
3Ease of operation
If conventional access control policies are used based on logged-in users, then user authentication is simplified, but fine-grained access control based on process classes is lost
Solution Approach 1:
The patent performs preliminary classification of processes into security classes during system initialization or process creation, establishing fine-grained access control boundaries before operations occur, while maintaining simple user authentication through token-based authorization
Data Source
AI summary
A cloud resource protection method, system, and computer program product include authenticating a user on a first computer that is part of a distributed system, based on the authentication, assigning to the user, on the first computer, a token indicating a set of permissions, receiving a directive from the user to initiate, via the first computer, the execution of a process associated with a class, based on the token, initiating, on a second computer, the execution of the process, with no further authentication, granting the process access to a data set, access to which is restricted to one or more of the plurality of classes, and providing a data item from the data set to the user.


