Multi-Account Access Control via Authorization Service

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Large organizations face challenges in managing computing resources across multiple accounts while ensuring security and compliance, particularly in complex systems with multiple users and resources, as implementing least privilege principles and scalable management of permissions can be difficult.

Innovation Solution

A service provider authorization service is used to provide customizable access to computing resources across multiple accounts, utilizing identity tokens with inherent and contained attributes to manage granular permissions and access through a many-to-many mapping system, enabling seamless programmatic access across disparate accounts and users.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If all computing resources are managed in one centrally managed account, then ease of operation is improved, but security and compliance are worsened due to inability to implement proper separation

Engineering Contradiction:
Improveease of managing computing resourcesVSAvoidsecurity and compliance
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments computing resources into multiple accounts organized by function, department, or project rather than managing all resources in a single account. This allows organizations to maintain separate accounts for different business units while still enabling controlled access across accounts through the authorization service, thus achieving both ease of management and security/compliance requirements

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an authorization service as an intermediary layer between users and computing resources across multiple accounts. This mediator handles cross-account access requests, evaluates permissions based on least privilege principles, and enforces access policies, thereby maintaining security while enabling operational flexibility across segmented accounts

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If separate accounts are used for different organizational units, then security and compliance are improved, but ease of operation is worsened due to difficulty in managing cross-account access

Engineering Contradiction:
Improvesecurity and complianceVSAvoidease of managing cross-account access
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The authorization service provides universal access control functionality across all accounts and resources. It implements a unified permission evaluation mechanism that works consistently across different account boundaries, resource types, and access scenarios, eliminating the need for separate access management systems for each account while maintaining security boundaries

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If least privilege principles are implemented in complex multi-user systems, then security is improved, but device complexity is worsened due to difficulty in managing granular permissions

Engineering Contradiction:
ImprovesecurityVSAvoidcomplexity of permission management system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent changes the parameters of permission management by shifting from managing detailed individual permissions to managing declarative access policies with wildcards and conditions. The authorization service evaluates these policies against user identities and resource contexts, automatically determining access decisions. This parameter transformation simplifies the management interface while maintaining granular security control through automated policy evaluation

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS10992657B1Multi-account entity based access control
Publication Date: 2021.04.27 AMAZON TECH INC
  • US10992657B1 patent drawing
  • US10992657B1 patent drawing
  • US10992657B1 patent drawing

AI summary

A plurality of attributes associated with a user of an account making a request is determined based on the received request. One or more operations to grant the user access to the one or more resources of the second account are determined based on the attributes. Access is provided to one or more resources of the second account according to the one or more operations to fulfill the request.