Cloud Security Control Platform Enforcing Permission-by-Permission Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Public cloud environments face significant security risks due to over-provisioned access to cloud services, dynamic and low-trust characteristics, and the lack of visibility into identity access needs, leading to high security exposure risks.

Innovation Solution

The Cloud Security Control Platform (CSCP) enforces security controls across multiple cloud environments, services, and teams, using a permission-by-permission evaluation model where all permissions are denied by default and granted only on an as-needed basis through a 'Permissions on Demand' mechanism.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If identity-centric mechanisms are used to provision access to cloud services, then ease of operation is improved, but security risk increases due to over-provisioned permissions

Engineering Contradiction:
Improveease of provisioning accessVSAvoidsecurity risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent inverts the traditional identity-centric access model by implementing permission-by-permission evaluation. Instead of granting broad permissions to identities and hoping for the best, the system starts with a default deny stance and evaluates each permission request individually based on actual job requirements. This inversion fundamentally changes the security posture from trust-based to verification-based access control.

Inventive Principle:
Principle #13The other way round (Inversion)

Solution Approach 2:

The patent applies local quality by evaluating permissions at a granular level rather than applying blanket policies to entire identities. Each permission is assessed independently against the specific job context and actual needs, allowing precise control over what each identity can access. This enables security policies to be tailored to the specific requirements of each permission rather than applying uniform restrictions or allowances.

Inventive Principle:
Principle #3Local quality

2Object-affected harmful factors

If comprehensive security controls are enforced across all cloud services, then security risk is reduced, but device complexity increases due to multiple control mechanisms

Engineering Contradiction:
Improvesecurity riskVSAvoidcomplexity of control mechanisms
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent implements a universal permission evaluation framework that works across diverse cloud services and identities through a common job context assessment mechanism. The system uses a standardized approach to evaluate whether each permission aligns with the identity's job requirements, regardless of the specific cloud service or permission type. This universal methodology simplifies the overall control architecture while maintaining comprehensive security coverage.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent changes the evaluation parameter from identity-level broad strokes to permission-level precision. By shifting the granularity of control from whole identities to individual permissions, the system achieves more effective security without proportionally increasing complexity. The permission-by-permission evaluation model allows for automated decision-making at a finer granularity, reducing the need for complex manual intervention while improving security posture.

Inventive Principle:
Principle #35Parameter changes

3Measurement precision

If permission-by-permission evaluation is implemented, then security control precision is improved, but productivity decreases due to increased approval requirements

Engineering Contradiction:
Improveprecision of security evaluationVSAvoidspeed of access provisioning
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The patent enables self-service access provisioning by implementing automated job context evaluation that can independently determine whether permission requests should be granted. The system automatically assesses whether each permission aligns with the identity's job requirements and grants access without requiring manual approval for routine cases. This self-service capability maintains high security precision while eliminating bottlenecks that would slow down access provisioning.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent performs preliminary evaluation of job contexts and permission requirements before access requests are made. By pre-establishing job contexts and defining what permissions are appropriate for each role, the system can quickly evaluate permission requests against these pre-defined criteria. This preliminary preparation enables rapid automated decision-making, maintaining both high precision in security evaluation and speed in access provisioning.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20250184369A1Cloud security control platform that enforces scope-based security controls
Publication Date: 2025.06.05 BIRD WILLIAM ALEXANDER
  • US20250184369A1 patent drawing
  • US20250184369A1 patent drawing
  • US20250184369A1 patent drawing

AI summary

A cloud security control platform and method enforces security controls across multiple cloud environments, services and disparate teams while providing a frictionless “Permissions on Demand” mechanism for approvals and exceptions. In contrast to the prior art, security is evaluated on a permission by permission basis, with the default being that all permissions are denied and then only given to a particular identity on an as-needed basis. This approach reduces the security risks associated with the vast capabilities available in Public Cloud environments and permits an organization that uses the platform to grant access, approve exceptions and delegate approvals with the appropriate compliance.