Directive-Based Access Control for Multi-Cloud Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional identity management systems in multi-cloud distributed systems face challenges in enforcing granular security directives across all levels of the hierarchy, managing multiple user roles, and tracking access privileges in real-time, leading to hidden assets and privileges that can result in anomalous behaviors and compliance issues.

Innovation Solution

A directive-based access control system utilizing a Lineage Traceability Enforcement Engine (LTE) and Directive Access Lineage Engine (DALE) to orchestrate secure communications by defining, managing, and enforcing security directives across multiple cloud systems, with features like auto-directive updates and behavioral monitoring.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traditional identity management systems are used to control access, then user authentication is performed, but granular security directives cannot be enforced at every level of the hierarchy

Engineering Contradiction:
Improvegranular security directive enforcementVSAvoidaccess control system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments access control into hierarchical levels (organizational, resource, and transaction levels) with specific directive types at each level. This allows granular enforcement of security policies at every tier of the system hierarchy, addressing the inability of traditional systems to enforce detailed security directives throughout the entire access chain.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a temporal dimension to access control by implementing time-bound directives with start and end times. This adds a time-based layer to the traditional hierarchical model, enabling dynamic enforcement of security policies that change over time while maintaining organizational structure.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Reliability

If role-based access control is implemented, then users with appropriate roles can access resources, but tracking access privileges becomes challenging when users have multiple roles

Engineering Contradiction:
Improveaccess privilege trackingVSAvoididentity management system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements continuous feedback mechanisms through real-time monitoring of user actions against applicable directives. The system constantly evaluates user behavior, checks compliance with active directives, and provides feedback for anomaly detection. This ensures reliable tracking of access privileges even when users hold multiple roles, as the system continuously verifies actions against the union of all applicable directives.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent creates a universal directive evaluation engine that handles multiple directive types (organizational, resource, transaction) and multiple user roles through a single unified system. This multi-functional approach consolidates the management of complex multi-role access control into one system that can evaluate any user against any applicable directive, reducing overall system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If traditional access control methods are used, then basic authentication is provided, but hidden assets and privileges lead to anomalous behaviors

Engineering Contradiction:
Improvedetection of anomalous behaviorsVSAvoidvisibility of hidden assets and privileges
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent implements continuous monitoring and evaluation of user actions against active directives throughout the entire access process. Rather than periodic checks, the system continuously evaluates each user action in real-time, ensuring that hidden assets and privileges are detected as they are accessed. This continuous action enables reliable detection of anomalous behaviors that might otherwise go unnoticed.

Inventive Principle:
Principle #20Continuity of useful action

Solution Approach 2:

The patent introduces an intermediary directive evaluation engine that sits between the user and the resources. This intermediary continuously monitors user actions, evaluates them against applicable directives, and detects anomalies. It acts as a mediator that provides visibility into hidden assets and privileges by intercepting and analyzing all access attempts, making the detection of anomalous behaviors more effective.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Adaptability or versatility

If static access privileges are assigned, then users have consistent access rights, but the system cannot adapt to changing scenarios and user roles

Engineering Contradiction:
Improveadaptation to changing scenariosVSAvoiddynamic access control system complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent transforms static access control into a dynamic system where directives have temporal validity periods with start and end times. Access privileges are no longer fixed but change dynamically based on the current time relative to directive time windows. The system automatically activates or deactivates directives based on temporal conditions, enabling adaptation to changing scenarios without manual intervention.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the temporal parameters of access control by introducing time-based validity periods for directives. Instead of static, permanent access rights, the system uses directed time windows during which specific access privileges are active. This parameter change from static to temporal enables the system to adapt to evolving requirements while maintaining a manageable directive structure.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11805126B2System and method for directives based mechanism to orchestrate secure communications in multi-cloud distributed systems
Publication Date: 2023.10.31 THUMMISI RAGHUNATHVENKATA RAMANA
  • US11805126B2 patent drawing
  • US11805126B2 patent drawing
  • US11805126B2 patent drawing

AI summary

A directive based access system and method manage access permissions in systems. In one embodiment, the directive based access system and method may be used to orchestrate effective secure access control and communications in multi-cloud distributed systems. In one implementation, the directive based access system and method may include a lineage traceability enforcement engine that uses a lineage traceability. The directive based access system and method may also be implemented using other mechanisms such as blockchain based Hyperledger based system.