Dynamic Authorization Delegation in Grid Computing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current grid computing solutions face challenges in providing flexible, on-demand authorization and authentication for entities accessing grid nodes, especially in real-time collaborative environments, as existing methods are not dynamic and require contact with a superauthority for certification.

Innovation Solution

A method for dynamic on-demand delegation of control in a grid computing environment, where a moderator with special access grants authority, modifies the access control list, and issues unique authorization certificates to other entities, allowing control without needing to contact the superauthority for certification, enabling scalable and dynamic access management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a separate asynchronous process like grid-map files is used for authorization, then authorization can be handled at a different level, but the system becomes static and difficult to tie with authentication in on-demand environments

Engineering Contradiction:
Improvedynamic authorizationVSAvoidauthorization process complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent merges authentication and authorization into a single integrated process. The authentication certificate contains both authentication information and authorization information, eliminating the need for separate asynchronous authorization processes. This integration allows the system to maintain adaptability while reducing the complexity of managing separate authorization mechanisms.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent implements dynamic authorization by allowing the authorization information in the certificate to be updated and revised. The system can dynamically adjust access rights and permissions based on current needs, transforming the static grid-map file approach into a dynamic, on-demand authorization mechanism that adapts to changing requirements.

Inventive Principle:
Principle #15Dynamics

2Reliability

If every end entity owns a X509 certificate and uses common PKI mechanisms, then authentication can be performed through trusted authority, but authorization becomes separate and requires additional processes

Engineering Contradiction:
Improveauthentication securityVSAvoidauthorization operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent combines authentication and authorization functions into a single certificate-based mechanism. The authentication certificate issued by the trusted authority contains both authentication credentials and authorization information, eliminating the need for separate authorization operations and simplifying the overall process while maintaining security.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The authentication certificate serves multiple functions: it provides authentication verification and simultaneously contains authorization information. This multi-functional certificate eliminates the need for separate authorization processes, making the system easier to operate while maintaining the security benefits of PKI mechanisms.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Adaptability or versatility

If grid computing involves running applications in diverse environments, then resource sharing and virtualization opportunities increase, but security issues and interoperability challenges arise

Engineering Contradiction:
Improveresource sharing capabilityVSAvoidsecurity infrastructure complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent creates a universal security mechanism where a single integrated certificate-based system handles both authentication and authorization across diverse grid environments. This universal approach simplifies the security infrastructure by providing a common mechanism that works across different environments, reducing the complexity of managing multiple security systems while enabling broad resource sharing.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS8935417B2Method and system for authorization and access control delegation in an on demand grid environment
Publication Date: 2015.01.13 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US8935417B2 patent drawing
  • US8935417B2 patent drawing
  • US8935417B2 patent drawing

AI summary

The method of the invention provides for dynamic on-demand delegation of control and access in a grid computing environment comprising granting authority of a grid node to a first moderator by a superauthority; admitting the first moderator to the grid node; modifying the access control list of the grid node by the first moderator; inviting other entities listed on the access control list to access the grid node; and issuing a unique authorization certificate to each of the other entities, wherein the first moderator controls the inviting of the other entities without contact with or accessing to the superauthority for certification.