Managed Application Objects Permission Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Data platforms face challenges in managing application permissions and ensuring secure execution of applications across consumer accounts, as existing solutions lack robust mechanisms for controlling application behavior and access to sensitive data objects.
Innovation Solution
A data platform system that allows providers to create application packages with defined permissions, enabling consumers to control the operations performed by applications, with mechanisms for authorization, object management, and secure access to external systems, using a combination of application roles, API integrations, and secret permissions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If applications are granted broad permissions to perform operations in consumer accounts, then application functionality and versatility are improved, but security risks and potential malicious behavior increase
Solution Approach 1:
The patent segments permissions into granular, discrete units that can be individually granted or revoked. Instead of all-or-nothing permission models, the system divides access rights into specific operations (e.g., read, write, execute) on specific objects, allowing consumers to grant only the minimum necessary permissions while maintaining application functionality.
Solution Approach 2:
The patent introduces an intermediary permission management layer between the application and consumer account resources. This intermediary system (including permission grants, revocations, and audits) mediates all access requests, enabling security control without blocking legitimate application operations.
2Object-affected harmful factors
If consumers implement strict permission controls to ensure security, then security risks are reduced, but application operation complexity increases
Solution Approach 1:
The patent creates universal permission objects that can be reused across multiple applications and consumer accounts. A single permission grant can serve multiple purposes, and the same permission management mechanisms handle diverse security requirements, reducing overall system complexity despite granular control.
Solution Approach 2:
The patent enables permission templates and reusable permission configurations that can be copied and applied across different contexts. Instead of manually configuring each permission individually, consumers can replicate proven permission sets, simplifying management while maintaining security.
3Productivity
If applications can access and modify consumer account objects freely, then application productivity is improved, but data loss and unauthorized modifications increase
Solution Approach 1:
The patent implements preliminary permission grants that are configured in advance before application execution. Consumers pre-approve specific operations on specific objects, creating a framework that enables efficient application operation while preventing unauthorized modifications before they can occur.
Solution Approach 2:
The patent incorporates feedback mechanisms including permission audits, access logging, and monitoring that provide continuous information about application actions. This feedback loop enables consumers to detect and respond to unauthorized operations while maintaining efficient legitimate application execution.
Data Source
AI summary
An application package and application instance for a data platform. The application is created in a consumer account of a consumer using the application package. The consumer grants permissions for performing privileged actions in the consumer account to an application role of the application. The application creates objects in the application, creates objects outside of the application in the consumer account, and accesses external systems using permissions granted by the consumer.


