Named Capability Access Control for Cloud Resource Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current orchestration systems in cloud computing face challenges in managing dynamic applications and preventing unauthorized access to resources within data centers, as they rely on static configurations and simplistic segregation methods, which are difficult to enforce and manage effectively.

Innovation Solution

The implementation of name-based capabilities that allow applications to identify and access resources securely by using a hierarchical naming system, cryptographic machinery, and chaperones to manage and restrict access, ensuring only authorized entities can access specific resources and services.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If orchestration systems use static configurations and simplistic segregation methods to manage resources, then device complexity is reduced, but security and authorization control deteriorate

Engineering Contradiction:
Improveorchestration system complexityVSAvoidauthorization control
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The system transforms static configuration parameters into dynamic capability parameters. Each resource access is governed by capability tokens that contain encoded authorization parameters, allowing the system to maintain simplicity while achieving robust security through parameter-based control rather than structural complexity

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

Capability tokens serve as intermediary objects between clients and resources. These tokens encapsulate authorization information and mediate access control, eliminating the need for complex orchestration logic while ensuring reliable authorization through cryptographic verification

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If orchestration systems create virtual machines and virtual networks based purely on segregation, then ease of operation is improved, but security enforceability deteriorates

Engineering Contradiction:
Improvevirtual network configurationVSAvoidsecurity enforceability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The capability-based system enables self-service security where each client automatically presents its capability token for verification. This eliminates manual security configuration while maintaining ease of operation, as the system autonomously enforces access control based on the cryptographic validity of capability tokens

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

Authorization is segmented into discrete capability tokens rather than relying on monolithic virtual network segregation. Each token represents a specific authorization grant, allowing fine-grained control while maintaining operational simplicity through token-based access management

Inventive Principle:
Principle #1Segmentation

3Adaptability or versatility

If applications are allowed to dynamically access resources in cloud environments, then adaptability is improved, but unauthorized access risk increases

Engineering Contradiction:
Improveapplication resource accessVSAvoidunauthorized access
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system implements dynamic authorization through capability tokens that can be issued, revoked, and updated without changing the underlying system structure. Applications can dynamically access resources by presenting valid capability tokens, achieving adaptability while security is maintained through cryptographic verification of token authenticity

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS10218704B2Resource access control using named capabilities
Publication Date: 2019.02.26 CISCO TECHNOLOGY INC
  • US10218704B2 patent drawing
  • US10218704B2 patent drawing
  • US10218704B2 patent drawing

AI summary

Aspects of the embodiments are directed to systems, methods, and computer program products embodied at a server managing a resource for providing access to a resource in a distributed network. Embodiments include receiving a request from a client for access to a resource, the request comprising a named capability identifying the resource and identifying a server managing the resource; determining, from the named capability, whether the client is authorized to access the resource identified by the named capability; and granting access to the resource named by the named capability based on the named capability received with the request.