Dynamic Security Policy Translation for Cloud Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Customers in cloud computing environments face difficulties in managing and expressing security policies due to differences in policy languages and interfaces, leading to challenges in controlling access to resources.

Innovation Solution

A graphical user interface (GUI) is provided to allow customers to specify security policies in a first policy language, which are then dynamically translated and evaluated by policy evaluation engines operating in a different policy language, enabling secure access control to resources in a multitenant computing environment.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If customers use different policy languages and interfaces to express security policies, then customers can choose their preferred format, but policy management complexity increases and compatibility issues arise

Engineering Contradiction:
Improvepolicy language choiceVSAvoidpolicy management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces a policy translation service as an intermediary component that receives security policies in various customer-preferred formats and translates them into a standardized internal representation. This mediator enables customers to use different policy languages while the system maintains uniform processing, thus preserving adaptability without increasing management complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system dynamically changes the parameter of policy language format by providing multiple input format options to customers while internally normalizing to a standard representation. This allows the system to adapt to different customer preferences (parameter variation) while maintaining consistent internal processing (parameter standardization), resolving the contradiction between versatility and complexity.

Inventive Principle:
Principle #35Parameter changes

2Adaptability or versatility

If security policies are statically defined, then policy evaluation is straightforward, but the system cannot adapt to changing security requirements dynamically

Engineering Contradiction:
Improvedynamic policy adaptationVSAvoidpolicy evaluation efficiency
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The patent implements dynamic security policies that can be modified at runtime without requiring system reconfiguration. The policy management system allows customers to update their security policies dynamically, and these changes are immediately reflected in policy evaluation. This dynamic capability enables adaptation to changing security requirements while maintaining evaluation efficiency through the standardized policy representation.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system performs preliminary translation of customer-specific policy formats into standardized internal representations before policy evaluation begins. This preliminary action prepares the policies in advance in a uniform format, enabling both dynamic adaptation capabilities and efficient evaluation processing, as the translation work is done beforehand rather than during evaluation.

Inventive Principle:
Principle #10Preliminary action

3Device complexity

If a unified policy language is enforced, then policy management becomes simpler, but customers lose the ability to use their preferred policy formats

Engineering Contradiction:
Improvepolicy management simplicityVSAvoidpolicy language flexibility
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The policy translation service acts as an intermediary layer between customers and the core policy evaluation system. Customers interact with the intermediary using their preferred formats, while the intermediary handles the conversion to unified internal representations. This mediator approach maintains simplicity in the core system while preserving flexibility in customer interactions.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements a universal policy translation capability that handles multiple policy language formats through a single translation service interface. This multi-functional approach allows the system to support diverse customer preferences while maintaining a unified internal policy representation, achieving both simplicity and flexibility simultaneously.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9934399B2Dynamic security policy generation
Publication Date: 2018.04.03 AMAZON TECH INC
  • US9934399B2 patent drawing
  • US9934399B2 patent drawing
  • US9934399B2 patent drawing

AI summary

A user interface is described, such as a graphical user interface (GUI), operable to receive a representation of a security policy expressed in a first policy language, where that security policy will be supported by policy evaluation engines (or other such components) that are configured to operate using security policies expressed using a second (different) policy language. The representation of the security policy is persisted in a data store in accordance with the first policy language. Subsequently, in response to receiving a request to access a resource, a second representation of the security policy is generated by translating the content of the security policy into a second policy language that is associated with the policy evaluation engine. The second representation of the security policy is then evaluated by the policy evaluation engine to grant or deny access to the resource.