Multi-Account Access Control via Authorization Service
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Large organizations face challenges in managing computing resources across multiple accounts while ensuring security and compliance, particularly in complex systems with multiple users and resources, as implementing least privilege principles and scalable management of permissions can be difficult.
Innovation Solution
A service provider authorization service is used to provide customizable access to computing resources across multiple accounts, utilizing identity tokens with inherent and contained attributes to manage granular permissions and access through a many-to-many mapping system, enabling seamless programmatic access across disparate accounts and users.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If all computing resources are managed in one centrally managed account, then ease of operation is improved, but security and compliance are worsened due to inability to implement proper separation
Solution Approach 1:
The patent segments computing resources into multiple accounts organized by function, department, or project rather than managing all resources in a single account. This allows organizations to maintain separate accounts for different business units while still enabling controlled access across accounts through the authorization service, thus achieving both ease of management and security/compliance requirements
Solution Approach 2:
The patent introduces an authorization service as an intermediary layer between users and computing resources across multiple accounts. This mediator handles cross-account access requests, evaluates permissions based on least privilege principles, and enforces access policies, thereby maintaining security while enabling operational flexibility across segmented accounts
2Reliability
If separate accounts are used for different organizational units, then security and compliance are improved, but ease of operation is worsened due to difficulty in managing cross-account access
Solution Approach 1:
The authorization service provides universal access control functionality across all accounts and resources. It implements a unified permission evaluation mechanism that works consistently across different account boundaries, resource types, and access scenarios, eliminating the need for separate access management systems for each account while maintaining security boundaries
3Reliability
If least privilege principles are implemented in complex multi-user systems, then security is improved, but device complexity is worsened due to difficulty in managing granular permissions
Solution Approach 1:
The patent changes the parameters of permission management by shifting from managing detailed individual permissions to managing declarative access policies with wildcards and conditions. The authorization service evaluates these policies against user identities and resource contexts, automatically determining access decisions. This parameter transformation simplifies the management interface while maintaining granular security control through automated policy evaluation
Data Source
AI summary
A plurality of attributes associated with a user of an account making a request is determined based on the received request. One or more operations to grant the user access to the one or more resources of the second account are determined based on the attributes. Access is provided to one or more resources of the second account according to the one or more operations to fulfill the request.


