Delegation Profiles for Secure Multi-Tenant Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing approaches for delegating security rights and privileges in electronic and multi-tenant environments are inefficient and lack secure, trusted methods for sharing permissions across heterogeneous services and resources, posing security concerns for service providers and customers.
Innovation Solution
The implementation of delegation profiles that include validation and authorization policies, allowing customers to dynamically authorize and manage access permissions for external entities, enabling secure and controlled access to resources through credential issuance and rule-based access determination.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If existing approaches for delegating security rights are used, then access to resources can be shared, but security concerns arise and the process is inefficient
Solution Approach 1:
The patent introduces a delegation profile as an intermediary mechanism that mediates between the customer's security requirements and the external entity's access needs. The delegation profile contains validation policies and authorization policies that act as intermediate rules to securely delegate permissions without compromising security or efficiency
Solution Approach 2:
The patent segments the permission delegation process into distinct components: validation policies (to verify external entities), authorization policies (to define permitted actions), and delegation profiles (to package and manage these policies). This segmentation allows for efficient processing while maintaining security through structured policy evaluation
2Adaptability or versatility
If customers want to delegate security privileges across heterogeneous services, then flexibility increases, but security control becomes more complex
Solution Approach 1:
The delegation profile is designed as a universal mechanism that can be applied across heterogeneous services and resources. The validation policy and authorization policy within the delegation profile provide multi-functional capabilities to handle different types of external entities and resource access scenarios through a single unified approach
Solution Approach 2:
The patent implements preliminary action by pre-defining validation policies and authorization policies within delegation profiles before actual resource access occurs. This allows customers to establish security rules in advance, simplifying the complexity of security management during runtime while maintaining flexibility for different access scenarios
Data Source
AI summary
Permissions can be delegated to enable access to resources associated with one or more different accounts, which might be associated with one or more different entities. Delegation profiles are established that are associated with at least one secured account of at least one customer. Each delegation profile includes information such as a name, a validation policy that specifies principals which may be external to the account and which are permitted to assume the delegation profile, and an authorization policy that indicates the permitted actions within the account for those principals which are acting within the delegation profile. Once a delegation profile is created, the profile can be available for external principals or services that provide a user credential delegated access under the account, where that credential is provided by a trusted identity service. Access can be provided across accounts using the user credential.


