Delegate Authorization System for Cloud Data Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional cloud computing environments lack the ability to control access to customer resources effectively, leading to security risks and unnecessary exposure of data to unauthorized users, as they often grant complete access to support users, failing to meet customers' specific security requirements.

Innovation Solution

A delegate authorization system that allows customers to selectively grant access to private data by determining authorized delegates based on predefined criteria, enabling controlled access and tracking of delegate activities for accountability, while filtering out unauthorized users and providing limited access privileges.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If complete access is granted to support users in conventional cloud environments, then issue resolution capability is improved, but data security and customer control deteriorate

Engineering Contradiction:
Improveissue resolution capabilityVSAvoiddata security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent segments the support user base into different delegate categories with distinct access levels and permissions. Instead of granting uniform complete access to all support users, the system divides them into authorized delegates with specific roles, allowing issue resolution capabilities to be distributed across multiple delegates while maintaining security through granular permission control.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements local quality by assigning different access permissions to different delegates based on their specific roles and requirements. Each delegate receives only the minimum necessary access rights for their specific task, rather than universal access. This allows issue resolution to proceed with appropriate access levels tailored to each delegate's needs.

Inventive Principle:
Principle #3Local quality

2Reliability

If selective access control is implemented, then data security is improved, but system complexity increases

Engineering Contradiction:
Improvedata securityVSAvoidaccess control system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates a universal delegate authorization framework that handles multiple access control scenarios through a single system. The authorization mechanism serves multiple functions: granting access, limiting access, tracking activities, and managing delegate relationships. This multi-functional approach reduces overall system complexity compared to implementing separate control mechanisms for each scenario.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system implements self-service capabilities where customers can independently manage their own delegate authorizations, view activity logs, and control access permissions without requiring provider intervention. This self-service aspect simplifies the overall system architecture by pushing management responsibilities to the customer side while maintaining security controls.

Inventive Principle:
Principle #25Self-service

3Reliability

If delegate authorization tracking is implemented, then accountability is improved, but processing overhead increases

Engineering Contradiction:
ImproveaccountabilityVSAvoidprocessing overhead
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements preliminary action by pre-configuring authorization templates and delegate roles before actual access is needed. Delegate permissions, activity tracking parameters, and authorization rules are established in advance, allowing the system to quickly grant or deny access without extensive real-time processing. This reduces processing overhead while maintaining comprehensive accountability tracking.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9672379B2Method and system for granting access to secure data
Publication Date: 2017.06.06 SALESFORCE INC
  • US9672379B2 patent drawing
  • US9672379B2 patent drawing
  • US9672379B2 patent drawing

AI summary

Techniques described herein can be implemented as one or a combination of methods, systems or processor executed code to form embodiments capable of improved protection of data or other computing resources based at least in part upon limiting access to a select number of delegates. Limited access to cloud data based on customer selected or other criterion, reducing the possibility of security exposures and/or improving privacy is provided for.