Delegation Profile System for Secure Cloud Permission Sharing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing approaches for delegating security rights and privileges in electronic and multi-tenant environments are inefficient and lack secure mechanisms for authorizing permissions across multiple services and resources, particularly in cloud computing scenarios, where ensuring secure access and managing permissions across heterogeneous systems is challenging.

Innovation Solution

The implementation of a delegation profile system that allows customers to dynamically create, assign, and manage permissions for external entities, using validation and authorization policies to grant access to resources, enabling secure and trusted sharing of privileges across multiple accounts and services.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If existing approaches for delegating security rights are used, then permission sharing between services is enabled, but security and control are compromised

Engineering Contradiction:
Improvepermission sharing capabilityVSAvoidsecurity control
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces a delegation profile as an intermediary mechanism that sits between the customer's credentials and the service access. This delegation profile contains validation and authorization policies that mediate the permission delegation process, allowing external entities to access services without directly compromising the customer's security credentials. The intermediary structure enables permission sharing while maintaining security control through policy-based authorization.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If manual permission management is implemented, then security control is maintained, but operational efficiency decreases

Engineering Contradiction:
Improvesecurity controlVSAvoidoperational efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements preliminary action by pre-defining validation policies and authorization policies within delegation profiles before they are needed. Customers can configure multiple delegation profiles with different permission sets in advance, specifying which external entities can assume which credentials and under what conditions. When permission delegation is needed, the system automatically selects and applies the appropriate pre-configured profile, eliminating the need for manual, real-time permission management while maintaining security control.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If dynamic credential assumption is allowed, then service flexibility is improved, but security risks increase

Engineering Contradiction:
Improveservice flexibilityVSAvoidsecurity risks
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements dynamic credential assumption through delegation profiles that can be selectively applied based on service requirements. The system dynamically determines which delegation profile to use and which credentials to assume based on the external entity's identity and the service context. This dynamic behavior is constrained by validation policies that verify the external entity's right to assume credentials and authorization policies that limit the scope of assumed credentials to only what is necessary for the specific service interaction, thus enabling flexibility while controlling security risks.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS10263994B2Authorized delegation of permissions
Publication Date: 2019.04.16 AMAZON TECH INC
  • US10263994B2 patent drawing
  • US10263994B2 patent drawing
  • US10263994B2 patent drawing

AI summary

Systems and methods are described for delegating permissions to enable account access to entities not directly associated with the account. The systems determine a delegation profile associated with a secured account of at least one customer. The delegation profile includes a name, a validation policy that specifies principals which may be external to the account and which are permitted to assume the delegation profile, and an authorization policy that indicates the permitted actions within the account for those principals which are acting within the delegation profile. Once the delegation profile is created, it can be provided to external principals or services. These external principals or services can use the delegation profile to obtain credentials for performing various actions in the account using the credentials of the delegation profile.