Cross-Account Role Chain Analysis for Unauthorized Access Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cloud computing platforms face security risks due to unintended cross-account access through roles, which can lead to unauthorized actions, posing a threat to data and resource security.

Innovation Solution

An account analyzer identifies roles that permit cross-account access and constructs a tree structure to visualize this access, allowing administrators to adjust permissions and prevent unauthorized access by removing permissions from inactive roles.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If roles are configured to permit cross-account access, then account versatility and collaboration are improved, but security risks and unauthorized access potential increase

Engineering Contradiction:
Improvecross-account access capabilityVSAvoidunauthorized access risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary analysis of role permissions and account access paths before unauthorized actions occur. By proactively identifying and flagging potential security risks in role configurations, the system prevents harmful actions before they can compromise account security.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system continuously monitors and analyzes account access patterns and role permissions, providing feedback about potential security risks. This feedback mechanism allows administrators to adjust role configurations to maintain both versatility and security, creating a closed-loop system that balances access needs with security concerns.

Inventive Principle:
Principle #23Feedback

2Measurement precision

If comprehensive role analysis is performed across multiple accounts, then security detection accuracy is improved, but system complexity and computational resources increase

Engineering Contradiction:
Improveunauthorized access detection accuracyVSAvoidanalysis system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system segments the complex multi-account analysis into manageable components by analyzing each account and role independently, then combining results to identify chain of roles. This segmentation approach maintains high detection accuracy while reducing overall system complexity through modular analysis.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system transitions from analyzing single-account permissions to multi-dimensional chain of roles analysis across account hierarchies. By visualizing access paths as tree structures and analyzing permissions across multiple dimensional layers, the system achieves comprehensive security detection without proportionally increasing complexity.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Reliability

If chain of roles analysis is performed to identify circuitous access paths, then security coverage is improved, but analysis time and processing duration increase

Engineering Contradiction:
Improvesecurity coverageVSAvoidanalysis time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary identification of entry point roles and potential access paths before conducting full chain analysis. By pre-processing role permission data and identifying high-risk configurations upfront, the system reduces the time required for comprehensive chain of roles analysis while maintaining complete security coverage.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system extracts and focuses analysis on critical chain of roles paths that present security risks, rather than analyzing all possible access paths equally. By identifying and concentrating computational resources on high-risk circulation paths, the system achieves comprehensive security coverage with reduced overall analysis time.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS12463976B2Methods and systems for detecting inadvertent unauthorized account access
Publication Date: 2025.11.04 MICROSOFT TECHNOLOGY LICENSING LLC
  • US12463976B2 patent drawing
  • US12463976B2 patent drawing
  • US12463976B2 patent drawing

AI summary

Methods, systems, apparatuses, and computer-readable storage mediums described herein are configured to automatically detect inadvertent, unauthorized account access. For example, a user account may be analyzed to identify roles thereof that permit identities of other accounts to assume the roles of the user account. The analysis is performed for each identified account, including any accounts having roles that permit identities of further accounts to assume the roles of the identified accounts. Accordingly, a chain of roles may be determined that indicates how one account may have access to another account via one or more intervening role assignments. This circuitous path of account access may be represented and displayed to a user, e.g., via a tree structure. Upon identifying an unauthorized account, an appropriate action may be performed to adjust permissions.