Geolocation-Based Just-In-Time Access for Cloud Data Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cloud computing environments face challenges in incident management and software deployment due to data control policies that limit access to restricted data and the control plane, often resulting in insufficient personnel and expertise to handle incidents effectively.

Innovation Solution

Implementing just-in-time (JIT) access mechanisms that allow DevOps personnel to access cloud computing resources on a limited and time-bound basis, with JIT policies governing access based on geolocation and screening criteria, ensuring that DevOps personnel do not obtain unauthorized access to restricted data or the control plane.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If data control policies restrict access to restricted data and control plane to authorized personnel only, then data security and compliance are improved, but incident management capability and response efficiency deteriorate due to insufficient personnel and expertise

Engineering Contradiction:
Improvedata securityVSAvoidincident management capability
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements dynamic access control where DevOps personnel are granted temporary access to restricted data and control plane only when incidents occur. The access rights are dynamically adjusted based on incident severity and automatically revoked after a predetermined time period, transforming static access restrictions into dynamic, context-aware permissions that balance security with operational needs

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent introduces an automated access management system that acts as an intermediary between security policies and incident response needs. This intermediary automatically evaluates incident conditions, determines appropriate access levels, grants temporary permissions to DevOps personnel, and automatically revokes access after the time period expires, eliminating the need for manual security approvals during incidents

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If more personnel are granted access to handle incidents, then incident management capability is improved, but data control and security compliance worsen due to increased access risks

Engineering Contradiction:
Improveincident management capabilityVSAvoiddata control
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system dynamically adjusts access permissions based on incident conditions, granting access only to DevOps personnel when incidents occur and automatically revoking access after a predetermined time period. This dynamic approach allows multiple personnel to access restricted data when needed for incident management while maintaining data control through automatic expiration of access rights

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent implements periodic access review where DevOps personnel are granted temporary access for a predetermined time period to resolve incidents. The access rights automatically expire after this period, creating a periodic pattern of access that enables incident management while maintaining long-term data control and security compliance

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS10924497B2Just-in-time access based on geolocation to maintain control of restricted data in cloud computing environments
Publication Date: 2021.02.16 MICROSOFT TECHNOLOGY LICENSING LLC
  • US10924497B2 patent drawing
  • US10924497B2 patent drawing
  • US10924497B2 patent drawing

AI summary

A JIT service in a cloud computing environment manages just-in-time access to resources in the cloud computing environment for an external device. When JIT access to a resource is requested by a device, the JIT service retrieves a JIT policy for the resource that includes geolocation criteria limiting the geolocation from which JIT access can be automatically granted. The geolocation of the device is evaluated against the geolocation criteria. If the geolocation criteria and any other criteria of the JIT policy are satisfied, the JIT service provisions JIT access to the resource for the device.