Multi-Party Resource Access Manager for Secure Computing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Managing access to computing-related resources becomes complex as the number of clients and services increases, particularly when multiple parties are involved in accessing a single resource, leading to difficulties in providing desired behavior.

Innovation Solution

Implementing a Multi-Party Resource Access Manager system that allows multiple distinct parties to independently control access to computing-related resources, where access requests are approved or denied based on combined access policies specified by each party, using a system that includes Software Application Registration, User Subscription And Authentication, and Resource Access Authorization services.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple independent parties are allowed to control access to computing-related resources, then security and access control are improved, but system complexity increases

Engineering Contradiction:
Improveaccess control securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary system that acts as a mediator between multiple independent parties and computing resources. This intermediary manages access policies, evaluates requests, and coordinates approvals/denials from multiple parties, thereby maintaining security without requiring direct complex interactions between all parties and resources.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The access control system is segmented into independent policy evaluation modules, each responsible for a specific party's access rules. This segmentation allows each party's access control logic to be managed separately while maintaining overall system security, reducing the complexity of managing all parties simultaneously.

Inventive Principle:
Principle #1Segmentation

2Measurement precision

If access policies from multiple parties are evaluated for each resource request, then access control accuracy is improved, but processing time increases

Engineering Contradiction:
Improveaccess control accuracyVSAvoidrequest processing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-evaluating and caching access policies from multiple parties before actual resource requests occur. Access policies are established and stored in advance, allowing the system to quickly retrieve and apply pre-determined rules rather than evaluating all party policies from scratch for each request.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback mechanisms where access policy evaluation results are cached and reused for subsequent similar requests. The system learns from previous evaluations and provides feedback to optimize future access control decisions, reducing redundant processing while maintaining accurate multi-party policy enforcement.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS9985969B1Controlling use of computing-related resources by multiple independent parties
Publication Date: 2018.05.29 AMAZON TECH INC
  • US9985969B1 patent drawing
  • US9985969B1 patent drawing
  • US9985969B1 patent drawing

AI summary

Techniques are described for managing access to computing-related resources that, for example, may enable multiple distinct parties to independently control access to the resources (e.g., such that a request to access a resource succeeds only if all of multiple associated parties approve that access). For example, an executing software application may, on behalf of an end user, make use of computing-related resources of one or more types that are provided by one or more remote third-party network services (e.g., data storage services provided by an online storage service)—in such a situation, both the developer user who created the software application and the end user may be allowed to independently specify access rights for one or more particular such computing-related resources (e.g., stored data files), such that neither the end user nor the software application developer user may later access those resources without the approval of the other party.