Dynamic Endpoint Access Control for Restricted Cloud Entities

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Configuring access control in highly restricted environments, such as private cloud substrates, is complex due to security restrictions that prevent administrators from directly accessing entities, and existing methods fail to account for diverse device types and network topologies, leading to inefficiencies and security risks.

Innovation Solution

An agent is inserted into restricted entities with a manifest, generating dynamic endpoints to connect to secure storage for access configuration retrieval, ensuring security and adaptability across different entity configurations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If administrators directly access entities in restricted environments to configure access control, then ease of operation is improved, but security restrictions are violated

Engineering Contradiction:
Improveease of access configurationVSAvoidsecurity restrictions
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an intermediary system (access manager with agent) that mediates between administrators and restricted entities. The agent runs inside the restricted environment and communicates with the access manager outside, allowing administrators to configure access control without directly accessing the restricted entities. This resolves the contradiction by providing ease of operation through automated configuration while maintaining security restrictions through the intermediary layer.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The agent automatically retrieves access configurations from secure storage and applies them to the restricted entity without requiring manual intervention from administrators. The system serves itself by autonomously managing access control configurations, eliminating the need for direct administrator access while maintaining security. This resolves the contradiction by providing ease of operation through automation while preserving security restrictions.

Inventive Principle:
Principle #25Self-service

2Ease of operation

If existing access control methods are used, then ease of operation is maintained, but adaptability to diverse device types and network topologies deteriorates

Engineering Contradiction:
Improveease of access configurationVSAvoidadaptability to diverse configurations
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The access manager system provides universal access control configuration capabilities that work across diverse device types and network topologies. The agent can retrieve and apply configurations to various entity types (computing devices, storage devices, network devices) through a unified interface. This resolves the contradiction by maintaining ease of operation through standardized procedures while achieving adaptability through multi-functional support for different configurations.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system adapts to diverse configurations by dynamically adjusting access control parameters based on the specific entity type and environment. The agent modifies configuration parameters such as API endpoints, authentication methods, and permission levels to match the requirements of different devices and network topologies. This resolves the contradiction by maintaining ease of operation through automated parameter adaptation while achieving versatility across different configurations.

Inventive Principle:
Principle #35Parameter changes

3Ease of operation

If administrators directly access APIs or commands in restricted environments, then ease of operation is improved, but security risks increase

Engineering Contradiction:
Improveease of access configurationVSAvoidsecurity risks
Core Design Contradiction:
Ease of operationVSObject-generated harmful factors

Solution Approach 1:

The access manager acts as an intermediary that retrieves access configurations from secure storage outside the restricted environment and delivers them to the agent inside. This eliminates the need for administrators to directly access APIs or commands within the restricted environment, reducing security risks while maintaining ease of operation through automated configuration delivery. The intermediary layer isolates administrators from direct exposure to restricted systems.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The agent automatically retrieves and applies access configurations without requiring administrators to manually access APIs or commands. The system performs self-service configuration management, eliminating human exposure to security risks associated with direct API access while maintaining operational ease through automation. The agent handles all security-sensitive operations autonomously within the restricted environment.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12413524B2Access control for restricted entities
Publication Date: 2025.09.09 SALESFORCE INC
  • US12413524B2 patent drawing
  • US12413524B2 patent drawing
  • US12413524B2 patent drawing

AI summary

Methods, apparatuses, and computer-program products are disclosed. A method may include activating, in a processing entity, a connection agent and a manifest, the manifest including a data signature and an endpoint type that are associated with the processing entity. The method may include generating, based on the data signature, the endpoint type, or both, one or more load balanced dynamic endpoints configured for access, by the connection agent and via one or more application programming interfaces, to a repository including access configurations for the processing entity. The method may include retrieving, via the one or more load balanced dynamic endpoints and from the repository, one or more first access configurations of the plurality of access configurations and the one or more first access configurations may be associated with the processing entity.