Delegation Profiles for Secure Multi-Tenant Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing approaches for delegating security rights and privileges in electronic and multi-tenant environments are inefficient and lack secure, trusted methods for sharing permissions across heterogeneous services and resources, posing security concerns for service providers and customers.

Innovation Solution

The implementation of delegation profiles that include validation and authorization policies, allowing customers to dynamically authorize and manage access permissions for external entities, enabling secure and controlled access to resources through credential issuance and rule-based access determination.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If existing approaches for delegating security rights are used, then access to resources can be shared, but security concerns arise and the process is inefficient

Engineering Contradiction:
Improveefficiency of permission delegationVSAvoidsecurity of resource access
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent introduces a delegation profile as an intermediary mechanism that mediates between the customer's security requirements and the external entity's access needs. The delegation profile contains validation policies and authorization policies that act as intermediate rules to securely delegate permissions without compromising security or efficiency

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the permission delegation process into distinct components: validation policies (to verify external entities), authorization policies (to define permitted actions), and delegation profiles (to package and manage these policies). This segmentation allows for efficient processing while maintaining security through structured policy evaluation

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If customers want to delegate security privileges across heterogeneous services, then flexibility increases, but security control becomes more complex

Engineering Contradiction:
Improveflexibility in permission sharingVSAvoidcomplexity of security management
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The delegation profile is designed as a universal mechanism that can be applied across heterogeneous services and resources. The validation policy and authorization policy within the delegation profile provide multi-functional capabilities to handle different types of external entities and resource access scenarios through a single unified approach

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent implements preliminary action by pre-defining validation policies and authorization policies within delegation profiles before actual resource access occurs. This allows customers to establish security rules in advance, simplifying the complexity of security management during runtime while maintaining flexibility for different access scenarios

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10097558B2Delegated permissions in a distributed electronic environment
Publication Date: 2018.10.09 AMAZON TECH INC
  • US10097558B2 patent drawing
  • US10097558B2 patent drawing
  • US10097558B2 patent drawing

AI summary

Permissions can be delegated to enable access to resources associated with one or more different accounts, which might be associated with one or more different entities. Delegation profiles are established that are associated with at least one secured account of at least one customer. Each delegation profile includes information such as a name, a validation policy that specifies principals which may be external to the account and which are permitted to assume the delegation profile, and an authorization policy that indicates the permitted actions within the account for those principals which are acting within the delegation profile. Once a delegation profile is created, the profile can be available for external principals or services that provide a user credential delegated access under the account, where that credential is provided by a trusted identity service. Access can be provided across accounts using the user credential.