Delegation Profile System for Secure Cloud Permission Sharing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing approaches for delegating security rights and privileges in electronic and multi-tenant environments are inefficient and lack secure mechanisms for authorizing permissions across multiple services and resources, particularly in cloud computing scenarios, where ensuring secure access and managing permissions across heterogeneous systems is challenging.
Innovation Solution
The implementation of a delegation profile system that allows customers to dynamically create, assign, and manage permissions for external entities, using validation and authorization policies to grant access to resources, enabling secure and trusted sharing of privileges across multiple accounts and services.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If existing approaches for delegating security rights are used, then permission sharing between services is enabled, but security and control are compromised
Solution Approach 1:
The patent introduces a delegation profile as an intermediary mechanism that sits between the customer's credentials and the service access. This delegation profile contains validation and authorization policies that mediate the permission delegation process, allowing external entities to access services without directly compromising the customer's security credentials. The intermediary structure enables permission sharing while maintaining security control through policy-based authorization.
2Reliability
If manual permission management is implemented, then security control is maintained, but operational efficiency decreases
Solution Approach 1:
The patent implements preliminary action by pre-defining validation policies and authorization policies within delegation profiles before they are needed. Customers can configure multiple delegation profiles with different permission sets in advance, specifying which external entities can assume which credentials and under what conditions. When permission delegation is needed, the system automatically selects and applies the appropriate pre-configured profile, eliminating the need for manual, real-time permission management while maintaining security control.
3Adaptability or versatility
If dynamic credential assumption is allowed, then service flexibility is improved, but security risks increase
Solution Approach 1:
The patent implements dynamic credential assumption through delegation profiles that can be selectively applied based on service requirements. The system dynamically determines which delegation profile to use and which credentials to assume based on the external entity's identity and the service context. This dynamic behavior is constrained by validation policies that verify the external entity's right to assume credentials and authorization policies that limit the scope of assumed credentials to only what is necessary for the specific service interaction, thus enabling flexibility while controlling security risks.
Data Source
AI summary
Systems and methods are described for delegating permissions to enable account access to entities not directly associated with the account. The systems determine a delegation profile associated with a secured account of at least one customer. The delegation profile includes a name, a validation policy that specifies principals which may be external to the account and which are permitted to assume the delegation profile, and an authorization policy that indicates the permitted actions within the account for those principals which are acting within the delegation profile. Once the delegation profile is created, it can be provided to external principals or services. These external principals or services can use the delegation profile to obtain credentials for performing various actions in the account using the credentials of the delegation profile.


