Cloud Resource Protection via Token-Based Process Class Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional cloud computing methods require hardware virtualization, which imposes performance overhead and security risks, and fail to effectively manage access control based on process or application classes across a cloud infrastructure.

Innovation Solution

A cloud resource protection method that authenticates users and assigns them tokens indicating permissions, allowing processes to execute and access restricted data sets without further authentication, using a non-virtualized cloud infrastructure and associating processes or applications with classes for access control policies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If hardware virtualization is used for cloud computing, then security control over virtual machines is improved, but performance overhead and CPU tax increase

Engineering Contradiction:
Improvesecurity controlVSAvoidperformance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent extracts the virtualization layer from the cloud infrastructure, eliminating hardware virtualization while retaining security controls through class-based access policies applied directly to processes and data on the underlying hardware platform

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent segments access control into fine-grained classes that can be applied to specific processes and data sets, replacing the coarse-grained virtual machine isolation approach with more granular, process-level security boundaries

Inventive Principle:
Principle #1Segmentation

2Reliability

If hardware virtualization is implemented, then security benefits are achieved, but memory overhead and system complexity increase

Engineering Contradiction:
Improvesecurity benefitsVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent removes the virtualization infrastructure from the system architecture, eliminating the associated memory overhead and complexity while maintaining security through a simplified class-based access control model operating directly on the hardware platform

Inventive Principle:
Principle #2Taking out (Extraction)

3Ease of operation

If conventional access control policies are used based on logged-in users, then user authentication is simplified, but fine-grained access control based on process classes is lost

Engineering Contradiction:
Improveauthentication simplicityVSAvoidaccess control granularity
Core Design Contradiction:
Ease of operationVSManufacturing precision

Solution Approach 1:

The patent performs preliminary classification of processes into security classes during system initialization or process creation, establishing fine-grained access control boundaries before operations occur, while maintaining simple user authentication through token-based authorization

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10742629B2Efficient cloud resource protection
Publication Date: 2020.08.11 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US10742629B2 patent drawing
  • US10742629B2 patent drawing
  • US10742629B2 patent drawing

AI summary

A cloud resource protection method, system, and computer program product include authenticating a user on a first computer that is part of a distributed system, based on the authentication, assigning to the user, on the first computer, a token indicating a set of permissions, receiving a directive from the user to initiate, via the first computer, the execution of a process associated with a class, based on the token, initiating, on a second computer, the execution of the process, with no further authentication, granting the process access to a data set, access to which is restricted to one or more of the plurality of classes, and providing a data item from the data set to the user.