Cloud Security Access Control via Rule-Based Mediation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cloud computing systems face challenges in providing secure, efficient, and reliable access to resources due to the growing need for greater security and control over client access.

Innovation Solution

A cloud computing security system with an access manager module and security logic module that utilize client profiles with sets of rules to grant access to cloud computing resources, enabling granular access control and compliance evaluation for access requests.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If cloud computing systems provide easy access to resources over the Internet, then user accessibility and ease of operation are improved, but security and control over client access deteriorate

Engineering Contradiction:
Improveuser accessibilityVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a security logic module as an intermediary component between clients and cloud computing resources. This module receives access requests from clients, evaluates them against defined rules, and mediates the access decision. The security logic module enables easy Internet-based access while maintaining security control, resolving the contradiction between accessibility and security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If the system implements comprehensive access control rules, then security and control are improved, but device complexity increases

Engineering Contradiction:
Improvesecurity controlVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the access control system into distinct components: client profiles containing rule sets, a security logic module for evaluation, and an access manager for coordination. This segmentation allows comprehensive security control to be achieved through modular, manageable components rather than a monolithic complex system.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements preliminary action by pre-defining access rules within client profiles before actual access requests occur. These rules are established in advance and stored in the security logic module, enabling rapid evaluation of access requests without complex real-time decision-making, thus reducing operational complexity while maintaining strong security control.

Inventive Principle:
Principle #10Preliminary action

3Manufacturing precision

If the system evaluates all access requests against defined rules, then access control precision is improved, but processing time and productivity deteriorate

Engineering Contradiction:
Improveaccess control precisionVSAvoidaccess request processing speed
Core Design Contradiction:
Manufacturing precisionVSProductivity

Solution Approach 1:

The patent applies partial action by evaluating access requests against only the relevant rules from the client's profile rather than all possible rules. The security logic module selectively applies rules based on the specific access request and client authorization, achieving precise access control while minimizing processing time by avoiding unnecessary rule evaluations.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS8726348B2Collaborative rules based security
Publication Date: 2014.05.13 THE BOEING CO
  • US8726348B2 patent drawing
  • US8726348B2 patent drawing
  • US8726348B2 patent drawing

AI summary

A cloud computing security system. An access manager module includes first and second client profiles. The first client profile has a first set of rules enabling access to a first set of cloud computing system resources, and the second client profile has a second set of rules enabling access to a second set of cloud computing system resources. A security logic module is in communication with the access manager module. The security logic module is configured to receive an access request for access to one of the first and second sets of cloud computing system resources. Responsive to determining that the access request complies with at least one of the first set of rules and the second set of rules, the security logic module is configured to provide an access grant that grants access to at least one of the first and second sets of cloud computing system resources.