Freeform Metadata Tags for Secure Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional approaches for managing freeform metadata, such as tags, in computing resources lack effective control mechanisms, leading to potential security breaches and inefficient access management in multitenant environments like cloud computing.
Innovation Solution
Implementing a system that allows users to assign freeform metadata tags to computing resources, which are then used as predicates in access control policies, while restricting tag modifications through access control lists and policies, ensuring secure and controlled access across heterogeneous resources.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If freeform metadata tags are allowed without control mechanisms, then flexibility and ease of operation are improved, but security and access control reliability deteriorate
Solution Approach 1:
The patent introduces access control lists (ACLs) and access control policies as intermediary mechanisms between users and tags. These intermediaries mediate tag assignment operations by evaluating whether the user has permission to assign the tag to the resource, thereby maintaining security while allowing flexible tag usage when authorized.
Solution Approach 2:
The patent segments access control into multiple components: tag-level permissions, resource-level permissions, and user-level permissions. This segmentation allows fine-grained control where different users can have different permissions for different tags on different resources, resolving the contradiction between flexibility and security.
2Adaptability or versatility
If access control policies are dynamically associated with tagged resources, then adaptability and productivity are improved, but system complexity increases
Solution Approach 1:
The patent creates a universal access control framework where the same ACL and policy mechanisms apply to all tags and resources consistently. This universal approach, while initially complex, provides long-term adaptability as the system can handle diverse tagging scenarios with a single unified mechanism rather than requiring separate solutions for each case.
Solution Approach 2:
The patent establishes access control policies and ACLs in advance before tag assignment operations occur. By pre-defining the rules and permissions, the system automatically evaluates these pre-set policies when tags are assigned, enabling dynamic adaptability without requiring complex real-time decision-making logic.
3Adaptability or versatility
If tag-based access control is implemented across heterogeneous resources, then versatility is improved, but measurement precision and control difficulty increase
Solution Approach 1:
The patent applies homogeneous access control mechanisms (ACLs and policies) uniformly across heterogeneous resources. By using the same control structure for different resource types, the system achieves versatility while managing complexity through consistency in the control approach, even though the resources themselves are diverse.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Approaches are described for security and access control for computing resources. Various embodiments utilize metadata, e.g., tags that can be applied to one or more computing resources (e.g., virtual machines, host computing devices, applications, databases, etc.) to control access to these and/or other computing resources. In various embodiments, the tags and access control policies described herein can be utilized in a multitenant shared resource environment.