Hybrid-Cloud Authorization Validation for Multi-Tenant Data Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing hybrid-cloud systems face security risks in multi-tenant environments where client devices can access data they are not permitted to access due to the inability of third-party authorization servers to validate requests accurately, leading to potential data breaches.
Innovation Solution
Implementing a trusted authorization server that checks the validity of requests from client devices before forwarding them to the third-party authorization server, ensuring access tokens are issued only to authorized devices by including tenant and organizational unit identifiers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a third-party authorization server is used to issue access tokens in a multi-tenant environment, then the system can support multiple tenants and scale capacity, but client devices can access data they are not permitted to access due to inability to validate requests accurately
Solution Approach 1:
The patent introduces a trusted authorization server as an intermediary between client devices and the third-party authorization server. This mediator validates requests from client devices before forwarding them to the third-party server, ensuring that only authorized requests receive access tokens. The intermediary resolves the contradiction by maintaining multi-tenant support while adding a layer of security validation that prevents unauthorized data access.
2Ease of operation
If access tokens are issued without validating client device requests, then the authorization process is simple and fast, but data breaches can occur when client devices access unauthorized data
Solution Approach 1:
The patent implements preliminary validation of client device requests before access tokens are issued. The trusted authorization server checks whether client devices are permitted to access requested data items before forwarding requests to the third-party authorization server. This preliminary action prevents unauthorized access attempts from proceeding, resolving the contradiction by maintaining operational simplicity while eliminating data breach risks through advance validation.
3Reliability
If a trusted authorization server validates requests before forwarding to third-party server, then data security is enhanced, but the authorization process becomes more complex
Solution Approach 1:
The patent segments the authorization process into distinct stages: request validation by the trusted authorization server, token issuance by the third-party server, and data access by client devices. This segmentation isolates the complexity of validation logic to a specific component while maintaining a clear, standardized interface with the third-party server. The segmentation resolves the contradiction by concentrating complexity in a manageable location while preserving overall system security.
Data Source
AI summary
A method is provided for controlling secure access to data in hybrid-cloud environments. A trusted authorisation server controls access to data served by a resource server to client devices in an untrusted environment, to ensure client devices are only able to access data that they are permitted to access. In the present techniques, the trusted authorisation server checks the validity of data access requests received from client devices prior to any such requests being received by the resource server or an authorisation server associated with the resource server. This is advantageous because in many existing hybrid-cloud systems, the resource server and authorisation server are unable to check the individual validity of requests received from client devices. This is particularly problematic for multi-tenant resource servers. The present techniques provide a more secure way of controlling access to data stored and served by cloud-based, off-premises/third party resource servers.


