Local Authorization Extension for Cloud Maintenance Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cloud computing environments face security insufficiencies and unauthorized access issues during maintenance, as existing systems rely on methods from non-virtualized computing centers, posing risks to data protection and stable operations.

Innovation Solution

A local authorization extension system that uses a hypervisor to manage access by defining validity ranges for location and service authorization modules via global positioning system receivers, ensuring only authorized personnel can access computing systems for maintenance, with communicative coupling and encryption for secure authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional access control methods from non-virtualized computing centers are used, then device complexity is reduced, but security insufficiencies occur and unauthorized access risks increase

Engineering Contradiction:
ImprovesecurityVSAvoidaccess control system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a nested authorization structure where a location authorization extension is integrated within the CPU, which itself is part of the hypervisor system. The extension contains validity range data and works in conjunction with position signals from GPS receivers, creating multiple layers of authorization checks that enhance security while maintaining system integration.

Inventive Principle:
Principle #7Nested doll (Nesting)

Solution Approach 2:

The location authorization extension acts as an intermediary component between the GPS position signals and the access control decisions. It receives position information, compares it against stored validity ranges, and provides authorization decisions to the hypervisor, thereby mediating between physical location data and system access control.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If location-based authorization is implemented, then unauthorized access is prevented, but device complexity and measurement requirements increase

Engineering Contradiction:
Improveaccess authorization securityVSAvoidposition signal verification
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The system performs preliminary actions by pre-storing validity range data (geographical coordinates and time periods) in the location authorization extension before access is needed. This allows the system to quickly compare real-time position signals against pre-defined acceptable ranges without requiring complex real-time calculations or external verification systems.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent changes the parameter of authorization from traditional credentials (passwords, tokens) to spatial-temporal parameters (geographical coordinates and time periods). The location authorization extension stores and processes these parameter changes, converting physical location data into authorization decisions that control system access.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS8990899B2Using a local authorization extension to provide access authorization for a module to access a computing system
Publication Date: 2015.03.24 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US8990899B2 patent drawing
  • US8990899B2 patent drawing
  • US8990899B2 patent drawing

AI summary

Provided are a method, system, and computer program product for a local authorization extension to provide access authorization for a module to access a computing system. A memory stores information on a first validity range comprising position coordinates for a module seeking to access the computing system and a second validity range comprising position coordinates for a location authorization extension for a computing system. A determination is made of a first position signal from a first receiver of the module and of a second position signal from a second receiver of the location authorization module. Determinations are made as to whether the first position signal is within the first validity range and whether the second position signal is within the second validity range. The module is granted access to the computing system in response to determining that the first position signal is within the first validity range and the second position signal is within the second validity range.