Command-Level Access Brokering for Cloud-Shifted Legacy OS
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing federated identity management systems are inadequate for providing command-level access to non-cloud ready operating systems like Windows 10 when migrating to the cloud, necessitating burdensome and insecure recreation of user accounts.
Innovation Solution
Employ a federated identity management approach with a command level communication brokering service for attribute-based access, using a passwordless credential-based OS communication protocol to link local credentials to the cloud platform's identity access management, enabling traceable session-level authentication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If Federated Identity Management systems are used for cloud migration, then user authentication across domains is enabled, but command-level access to non-cloud operating systems cannot be provided
Solution Approach 1:
The patent introduces a command-level access broker as an intermediary component that sits between the Federated Identity Management system and the non-cloud operating system. This broker translates federated identity authentication into command-level access permissions, enabling both cross-domain authentication and fine-grained command control. The broker mediates the communication between the cloud-based FIM system and the legacy OS, resolving the contradiction by adding a layer that bridges these incompatible systems.
2Reliability
If user credentials are relocated to the cloud platform, then access control is improved, but the process becomes burdensome and time-consuming
Solution Approach 1:
The patent implements preliminary action by pre-configuring the command-level access broker with role-based access control policies before the migration process. The broker is pre-loaded with mapping rules that automatically translate federated identity claims into appropriate command permissions. This preliminary setup eliminates the need for manual credential relocation and provisioning for each user, as the system automatically provisions access based on pre-defined roles and policies.
Solution Approach 2:
The access broker implements self-service by automatically handling user provisioning and access control without requiring manual intervention. When users authenticate through the Federated Identity Management system, the broker automatically evaluates their claims against pre-defined policies and grants appropriate command-level access. This self-service mechanism eliminates the burdensome manual process of relocating and configuring credentials for each user individually.
3Reliability
If individual user accounts are recreated in the cloud environment, then security and traceability are improved, but device complexity and operational burden increase
Solution Approach 1:
The patent applies universality by implementing a universal command-level access broker that handles multiple functions: authentication, authorization, session management, and audit logging. Instead of creating separate mechanisms for each of these functions, the broker provides a unified system that performs all access control operations for non-cloud applications in the cloud environment. This multi-functional approach reduces device complexity while maintaining security and traceability.
Solution Approach 2:
The patent utilizes parameter changes by transforming the access control model from traditional user-account based parameters to role-based access control parameters. Instead of managing individual user accounts with unique credentials and permissions, the system changes the parameter to role-based policies that define access rights. This parameter transformation simplifies the management complexity while maintaining the ability to trace and control access at the command level for security and auditing purposes.
Data Source
AI summary
Per one example embodiment, a method is provided of shifting an OS (operating system) and associated native application platform from a private network to a cloud-based target environment, where the OS comprises an operating system not configured for web access. An image of the OS is provided that is suitable for installation on a target virtual machine in the cloud-based target platform. In lieu of moving user credentials of numerous current private network-based users of the OS—native application platform to the target environment, a passwordless credential-based OS command level communication brokering service is provided at the cloud-based target environment.


