Dynamic Identity Consolidation for Multi-Group Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In cloud computing environments, users belonging to multiple Active Directory (AD) groups face difficulties accessing all necessary resources due to the legacy design of resource provider environments, where they can only assume one identity at a time, limiting access to resources distributed across multiple identities.

Innovation Solution

The solution involves dynamically generating a new identity in the resource provider environment that consolidates policies from multiple AD groups, allowing users to access all resources associated with their respective identities, thereby enabling access to resources that would otherwise require multiple logins or external data storage.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If users assume one identity at a time in legacy resource provider environments, then security protocols are maintained, but users cannot access resources distributed across multiple identities

Engineering Contradiction:
Improveaccess to resourcesVSAvoiduser productivity
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent merges multiple identities associated with a user into a single consolidated identity. The identity consolidation service combines security policies from multiple source identities into a target identity, allowing users to access resources from all source identities through one unified identity without compromising security protocols.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The consolidated identity serves multiple functions by inheriting and combining access permissions from multiple source identities. This universal identity enables users to perform tasks across different resource types and identities without needing separate login credentials for each.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If multiple logins are required to access resources from multiple identities, then access control is maintained, but user productivity decreases

Engineering Contradiction:
Improveaccess controlVSAvoiduser productivity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

Multiple identities are merged into a single consolidated identity that preserves the access control policies from all source identities. Users log in once with their federated credentials and assume the consolidated identity, which automatically enforces the combined security policies while eliminating the need for multiple logins.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The identity consolidation service acts as an intermediary that translates federated identity credentials into a consolidated resource provider identity. This mediator layer maintains security by enforcing policies from all source identities while simplifying user authentication to a single login process.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If external data storage is used to bridge identities, then resource access is enabled, but system complexity increases

Engineering Contradiction:
Improveresource accessVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

Instead of using external data storage to bridge identities, the patent merges the identities directly within the resource provider environment. The consolidation service combines security policies and access permissions into a unified identity structure, eliminating the need for external storage intermediaries and reducing system complexity.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS11539707B2Dynamic security policy consolidation
Publication Date: 2022.12.27 AMAZON TECH INC
  • US11539707B2 patent drawing
  • US11539707B2 patent drawing
  • US11539707B2 patent drawing

AI summary

Various embodiments provide for the consolidation of policies across multiple identities that are respectively associated with multiple active directory (AD) groups to which a user belongs. Present embodiments provide for dynamically generating a new identity in the resource provider environment that includes permissions to all of the resources that may otherwise be distributed across multiple identities. Specifically, in accordance with various embodiments, when a user login is detected, the active directory is queried to determine the AD groups to which the user belongs. As mentioned, the user's AD groups are mapped to respective identities in the resource provider environment, in which each identity includes policy defining access to one or more resources. The policies of all the respective identities are consolidated and assigned to a new identity. The user may assume the new identity and access all the resources in tandem.