Cloud Security Control Platform Enforcing Permission-by-Permission Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Public cloud environments face significant security risks due to over-provisioned access to cloud services, dynamic and low-trust characteristics, and the lack of visibility into identity access needs, leading to high security exposure risks.
Innovation Solution
The Cloud Security Control Platform (CSCP) enforces security controls across multiple cloud environments, services, and teams, using a permission-by-permission evaluation model where all permissions are denied by default and granted only on an as-needed basis through a 'Permissions on Demand' mechanism.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If identity-centric mechanisms are used to provision access to cloud services, then ease of operation is improved, but security risk increases due to over-provisioned permissions
Solution Approach 1:
The patent inverts the traditional identity-centric access model by implementing permission-by-permission evaluation. Instead of granting broad permissions to identities and hoping for the best, the system starts with a default deny stance and evaluates each permission request individually based on actual job requirements. This inversion fundamentally changes the security posture from trust-based to verification-based access control.
Solution Approach 2:
The patent applies local quality by evaluating permissions at a granular level rather than applying blanket policies to entire identities. Each permission is assessed independently against the specific job context and actual needs, allowing precise control over what each identity can access. This enables security policies to be tailored to the specific requirements of each permission rather than applying uniform restrictions or allowances.
2Object-affected harmful factors
If comprehensive security controls are enforced across all cloud services, then security risk is reduced, but device complexity increases due to multiple control mechanisms
Solution Approach 1:
The patent implements a universal permission evaluation framework that works across diverse cloud services and identities through a common job context assessment mechanism. The system uses a standardized approach to evaluate whether each permission aligns with the identity's job requirements, regardless of the specific cloud service or permission type. This universal methodology simplifies the overall control architecture while maintaining comprehensive security coverage.
Solution Approach 2:
The patent changes the evaluation parameter from identity-level broad strokes to permission-level precision. By shifting the granularity of control from whole identities to individual permissions, the system achieves more effective security without proportionally increasing complexity. The permission-by-permission evaluation model allows for automated decision-making at a finer granularity, reducing the need for complex manual intervention while improving security posture.
3Measurement precision
If permission-by-permission evaluation is implemented, then security control precision is improved, but productivity decreases due to increased approval requirements
Solution Approach 1:
The patent enables self-service access provisioning by implementing automated job context evaluation that can independently determine whether permission requests should be granted. The system automatically assesses whether each permission aligns with the identity's job requirements and grants access without requiring manual approval for routine cases. This self-service capability maintains high security precision while eliminating bottlenecks that would slow down access provisioning.
Solution Approach 2:
The patent performs preliminary evaluation of job contexts and permission requirements before access requests are made. By pre-establishing job contexts and defining what permissions are appropriate for each role, the system can quickly evaluate permission requests against these pre-defined criteria. This preliminary preparation enables rapid automated decision-making, maintaining both high precision in security evaluation and speed in access provisioning.
Data Source
AI summary
A cloud security control platform and method enforces security controls across multiple cloud environments, services and disparate teams while providing a frictionless “Permissions on Demand” mechanism for approvals and exceptions. In contrast to the prior art, security is evaluated on a permission by permission basis, with the default being that all permissions are denied and then only given to a particular identity on an as-needed basis. This approach reduces the security risks associated with the vast capabilities available in Public Cloud environments and permits an organization that uses the platform to grant access, approve exceptions and delegate approvals with the appropriate compliance.


