Freeform Metadata Tags for Secure Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional approaches for managing freeform metadata, such as tags, in computing resources lack effective control mechanisms, leading to potential security breaches and inefficient access management in multitenant environments like cloud computing.

Innovation Solution

Implementing a system that allows users to assign freeform metadata tags to computing resources, which are then used as predicates in access control policies, while restricting tag modifications through access control lists and policies, ensuring secure and controlled access across heterogeneous resources.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If freeform metadata tags are allowed without control mechanisms, then flexibility and ease of operation are improved, but security and access control reliability deteriorate

Engineering Contradiction:
Improveflexibility in tag assignmentVSAvoidaccess control security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces access control lists (ACLs) and access control policies as intermediary mechanisms between users and tags. These intermediaries mediate tag assignment operations by evaluating whether the user has permission to assign the tag to the resource, thereby maintaining security while allowing flexible tag usage when authorized.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments access control into multiple components: tag-level permissions, resource-level permissions, and user-level permissions. This segmentation allows fine-grained control where different users can have different permissions for different tags on different resources, resolving the contradiction between flexibility and security.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If access control policies are dynamically associated with tagged resources, then adaptability and productivity are improved, but system complexity increases

Engineering Contradiction:
Improvedynamic access controlVSAvoidsystem architecture complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent creates a universal access control framework where the same ACL and policy mechanisms apply to all tags and resources consistently. This universal approach, while initially complex, provides long-term adaptability as the system can handle diverse tagging scenarios with a single unified mechanism rather than requiring separate solutions for each case.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent establishes access control policies and ACLs in advance before tag assignment operations occur. By pre-defining the rules and permissions, the system automatically evaluates these pre-set policies when tags are assigned, enabling dynamic adaptability without requiring complex real-time decision-making logic.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If tag-based access control is implemented across heterogeneous resources, then versatility is improved, but measurement precision and control difficulty increase

Engineering Contradiction:
Improvecross-resource access controlVSAvoidpolicy evaluation complexity
Core Design Contradiction:
Adaptability or versatilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent applies homogeneous access control mechanisms (ACLs and policies) uniformly across heterogeneous resources. By using the same control structure for different resource types, the system achieves versatility while managing complexity through consistency in the control approach, even though the resources themselves are diverse.

Inventive Principle:
Principle #33Homogeneity

Data Source

PatentEP2948840B1Use of freeform metadata for access control
Publication Date: 2020.08.12 AMAZON TECH INC
  • EP2948840B1 patent drawingFigure 1
  • EP2948840B1 patent drawingFigure 2
  • EP2948840B1 patent drawingFigure 3

AI summary

Approaches are described for security and access control for computing resources. Various embodiments utilize metadata, e.g., tags that can be applied to one or more computing resources (e.g., virtual machines, host computing devices, applications, databases, etc.) to control access to these and/or other computing resources. In various embodiments, the tags and access control policies described herein can be utilized in a multitenant shared resource environment.