Privacy-Preserving Secure Access Through Identity-Entitlement Separation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Cloud-delivered secure access solutions compromise enterprise privacy by exposing user identities and entitlements to cloud providers, violating the privacy concerns of enterprises.
Innovation Solution
Implementing a system where user identities are separated from entitlements, with independent authentication and authorization mechanisms, ensuring that only the enterprise knows the user identities and accessed resources, while cloud vendors remain unaware of this information.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If cloud-delivered secure access solutions are implemented, then secure access to resources is improved, but enterprise privacy deteriorates due to exposure of user identities and entitlements to cloud providers
Solution Approach 1:
The patent segments the authentication system into separate components: identity provider service (manages user identities), access provider service (manages resource access), and entitlements. This segmentation allows each component to operate independently with limited knowledge about others, preventing any single cloud provider from obtaining complete user identity and access information.
Solution Approach 2:
The patent introduces an intermediary entitlements system that acts as a mediator between the identity provider and access provider. The entitlements contain access permissions without revealing user identities to the access provider or resource details to the identity provider, thus preserving privacy while enabling secure access control.
2Ease of operation
If user identity is integrated into cloud-delivered secure access solutions, then access control functionality is improved, but privacy preservation deteriorates as cloud providers gain access to user information
Solution Approach 1:
The patent extracts user identity information from the access control process. The identity provider service handles identity management separately, while the access provider service only receives entitlements without user identity details. This extraction allows access control to function properly while removing the privacy-violating element of exposing user identities to cloud providers.
Solution Approach 2:
The patent applies local quality by giving different services different levels of information access based on their specific needs. The identity provider service has full identity information, the access provider service has only entitlements, and the resource service has only access requests. Each service operates with the minimum necessary information for its function, preserving privacy while maintaining operational effectiveness.
Data Source
AI summary
Techniques for preserving privacy while still allowing secure access to private resources. Among other things, the techniques may include receiving a request to provide a remote device with access to a private resource. In some instances, the request may be redirected to an identity provider service to authenticate the user of the remote device to maintain anonymity of an identity of the user. The techniques may also include receiving an indication of an entitlement-set provided by the identity provider service, the indication of the entitlement-set indicative of whether the user is entitled to access the resource without revealing the identity of the user. The techniques may also include at least one of authorizing the remote device to access the resource or refraining from authorizing the remote device to access the resource based at least in part on the indication of the entitlement-set.


