Dynamic Scoped Permission Control Plane for Compute Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current computing systems face security risks due to static permissions that grant broad access, allowing surreptitious operations across large scopes of computing resources, which can compromise data integrity and security.

Innovation Solution

A control plane dynamically identifies a target scope for each management task request, generating an approval request specific to that scope, thereby reducing the operational scope and enhancing security by limiting access to only necessary resources.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If static permissions are granted for broad scope of computing resources, then the control plane can perform management tasks across entire compute capacity, but security risks increase and surreptitious operations become more likely

Engineering Contradiction:
Improvescope of management operationsVSAvoidsecurity risks
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements dynamic permission granting where the control plane receives permissions for a specific target scope at the time of each management task request, rather than having static broad permissions. This dynamic approach allows the system to maintain versatility in performing management tasks across different resource scopes while minimizing security risks by limiting permission scope to only what is necessary for each specific task.

Inventive Principle:
Principle #15Dynamics

2Ease of operation

If static permissions cover entire compute capacity, then management tasks can be performed across all resources, but the likelihood of surreptitious actions increases

Engineering Contradiction:
Improveability to perform management tasksVSAvoidintegrity of operations
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the broad compute capacity into smaller target scopes, where each management task is granted permissions for a specific, limited scope rather than access to the entire system. This segmentation maintains ease of operation by allowing management tasks to be performed on necessary resources while improving reliability by isolating potential surreptitious actions to smaller, more controllable scopes.

Inventive Principle:
Principle #1Segmentation

3Adaptability or versatility

If broad permissions are granted to control plane, then management flexibility is improved, but security compromise risk increases

Engineering Contradiction:
Improvemanagement task flexibilityVSAvoidsecurity compromise risk
Core Design Contradiction:
Adaptability or versatilityVSObject-generated harmful factors

Solution Approach 1:

The system dynamically determines and grants permissions for specific target scopes at the time of each management task request. This dynamic permission model maintains management flexibility by adapting to the specific requirements of each task while reducing security compromise risk by ensuring that permissions are never broader than necessary for the current operation.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS12067422B2Dynamically acquiring scoped permissions to perform operations in compute capacity and resources
Publication Date: 2024.08.20 MICROSOFT TECHNOLOGY LICENSING LLC
  • US12067422B2 patent drawing
  • US12067422B2 patent drawing
  • US12067422B2 patent drawing

AI summary

A control plane in a computing system receives a request to perform a management task on a set of computing system resources. The control plane identifies a target scope on which the management task is to be performed and dynamically obtains permissions, for this specific request, to perform the management task on the resources in the identified target scope.