Cloud Security Access Control via Rule-Based Mediation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Cloud computing systems face challenges in providing secure, efficient, and reliable access to resources due to the growing need for greater security and control over client access.
Innovation Solution
A cloud computing security system with an access manager module and security logic module that utilize client profiles with sets of rules to grant access to cloud computing resources, enabling granular access control and compliance evaluation for access requests.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If cloud computing systems provide easy access to resources over the Internet, then user accessibility and ease of operation are improved, but security and control over client access deteriorate
Solution Approach 1:
The patent introduces a security logic module as an intermediary component between clients and cloud computing resources. This module receives access requests from clients, evaluates them against defined rules, and mediates the access decision. The security logic module enables easy Internet-based access while maintaining security control, resolving the contradiction between accessibility and security.
2Reliability
If the system implements comprehensive access control rules, then security and control are improved, but device complexity increases
Solution Approach 1:
The patent segments the access control system into distinct components: client profiles containing rule sets, a security logic module for evaluation, and an access manager for coordination. This segmentation allows comprehensive security control to be achieved through modular, manageable components rather than a monolithic complex system.
Solution Approach 2:
The patent implements preliminary action by pre-defining access rules within client profiles before actual access requests occur. These rules are established in advance and stored in the security logic module, enabling rapid evaluation of access requests without complex real-time decision-making, thus reducing operational complexity while maintaining strong security control.
3Manufacturing precision
If the system evaluates all access requests against defined rules, then access control precision is improved, but processing time and productivity deteriorate
Solution Approach 1:
The patent applies partial action by evaluating access requests against only the relevant rules from the client's profile rather than all possible rules. The security logic module selectively applies rules based on the specific access request and client authorization, achieving precise access control while minimizing processing time by avoiding unnecessary rule evaluations.
Data Source
AI summary
A cloud computing security system. An access manager module includes first and second client profiles. The first client profile has a first set of rules enabling access to a first set of cloud computing system resources, and the second client profile has a second set of rules enabling access to a second set of cloud computing system resources. A security logic module is in communication with the access manager module. The security logic module is configured to receive an access request for access to one of the first and second sets of cloud computing system resources. Responsive to determining that the access request complies with at least one of the first set of rules and the second set of rules, the security logic module is configured to provide an access grant that grants access to at least one of the first and second sets of cloud computing system resources.


