Container Access Restriction via Security Resource Profiles

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems face challenges in securely accessing data objects in a datastore by remote systems without user-specific credentials, particularly in container and resource access restriction scenarios, where traditional authentication methods are cumbersome and prone to security vulnerabilities.

Innovation Solution

A computer-implemented method using a processor to verify access entities through a security resource profile, allowing access to data objects without requiring user-specific credentials, by utilizing a security application program interface (API) to determine if access is permitted based on predefined security resource profiles.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional authentication methods with user-specific credentials are used, then access control security is maintained, but administrative complexity and security vulnerability increase

Engineering Contradiction:
Improveaccess control securityVSAvoidadministrative complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the credential verification step from the authentication process. Instead of requiring user-specific credentials to be verified, the system verifies access based on the access entity's inherent attributes and the security resource profile, effectively removing the credential verification burden while maintaining security.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a security resource profile as an intermediary between the access entity and the data object. This profile acts as a mediator that defines access rights and restrictions without requiring direct credential verification, simplifying the authentication process while maintaining security controls.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If user-specific credentials are required for access, then access authorization is precise, but risk of credential exposure and administrative overhead increase

Engineering Contradiction:
Improveaccess authorization precisionVSAvoidcredential exposure risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent removes credentials from the authentication equation entirely. Instead of verifying user-specific credentials, the system determines access based on the access entity's identity and the security resource profile, eliminating credential exposure risk while maintaining precise access control.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system performs self-verification by checking the access entity's inherent attributes against the security resource profile. The access entity itself provides the necessary identification information without requiring external credential validation, reducing administrative overhead and credential exposure risk.

Inventive Principle:
Principle #25Self-service

3Ease of operation

If security resource profiles are implemented without user-specific credentials, then administrative complexity is reduced, but access verification robustness must be maintained

Engineering Contradiction:
Improveadministrative simplicityVSAvoidaccess verification robustness
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The security resource profile serves as a robust intermediary that contains detailed access control rules and restrictions. This profile maintains verification robustness by defining specific conditions under which access is granted or denied, while the overall system remains simple to administer by not requiring credential management.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The security resource profile is pre-configured with all necessary access control rules and restrictions before access attempts occur. This preliminary setup maintains verification robustness by having all decision logic prepared in advance, while simplifying administration by eliminating the need for runtime credential verification.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11943226B2Container and resource access restriction
Publication Date: 2024.03.26 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US11943226B2 patent drawing
  • US11943226B2 patent drawing
  • US11943226B2 patent drawing

AI summary

A computer-implemented system and related method secures the access of a data object in a datastore by a remote system without user-specific credentials. The method comprises using a processor of a data resident operating system for verifying, using a security resource profile for the datastore, which access entity the remote system has access to, but without the user-specific credentials. The method also provides the security resource profile through a security application program interface (API) to the processor to determine whether access to the access entity should be allowed. The method allows the access to the data object by the remote system when the security resource profile exists and permits the access.