Privilege Revocation Service for Cloud Computing Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Customers who utilize computing resources from a provider entity face challenges in disabling administrative access to maintain privacy, prevent unauthorized access, and ensure compliance, as existing systems lack robust mechanisms to revoke administrative privileges without allowing regaining access by the provider entity.

Innovation Solution

The implementation of a privilege revocation service that restricts administrative access to computing devices, allowing customers to disable administrative privileges, which can only be regained through interrupting the operation of the computing device, such as a hardware or software reset, ensuring secure and controlled access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If administrative access is maintained for infrastructure maintenance and support, then system reliability and operational capability are improved, but security risk and unauthorized access increase

Engineering Contradiction:
Improvesystem operational capabilityVSAvoidunauthorized access risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments administrative access into two distinct states: enabled state for infrastructure maintenance and disabled state for customer data privacy. The privilege revocation service implements this segmentation by allowing customers to selectively disable administrative privileges while maintaining the ability to re-enable them through controlled reset mechanisms, thus resolving the contradiction between operational capability and security risk

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements dynamic administrative access control where the access state can change based on customer requests and system conditions. The privilege revocation service dynamically adjusts administrative privileges by processing customer requests to disable/enable access, and automatically restores access after device resets, making the system adaptable to different security and operational requirements

Inventive Principle:
Principle #15Dynamics

2Object-affected harmful factors

If administrative privileges are disabled to prevent unauthorized access, then security and data privacy are improved, but system maintainability and administrative support capability deteriorate

Engineering Contradiction:
Improveunauthorized access preventionVSAvoidsystem maintainability
Core Design Contradiction:
Object-affected harmful factorsVSEase of manufacture

Solution Approach 1:

The patent applies preliminary action by implementing a privilege revocation service that proactively disables administrative privileges before potential unauthorized access occurs. The service is configured to automatically restore administrative access after device resets, ensuring that the system maintains security while preserving maintainability through automated privilege restoration

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The privilege revocation service acts as an intermediary between customer security requirements and infrastructure maintenance needs. It mediates the contradiction by implementing a layered access control mechanism that allows customers to disable administrative access for security while the service itself maintains the capability to restore access for legitimate maintenance operations through reset mechanisms

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If administrative access is continuously enabled for support tasks, then operational efficiency is improved, but compliance with data privacy and legal requirements deteriorates

Engineering Contradiction:
Improveoperational efficiencyVSAvoidcompliance with legal requirements
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent implements periodic action through the automated restoration of administrative privileges after device resets. The privilege revocation service periodically checks and restores access rights, ensuring that administrative capabilities are temporarily suspended for compliance but automatically restored when needed for operational efficiency, thus balancing compliance and productivity

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS9432374B1Disabling administrative access to computing resources
Publication Date: 2016.08.30 AMAZON TECH INC
  • US9432374B1 patent drawing
  • US9432374B1 patent drawing
  • US9432374B1 patent drawing

AI summary

Disclosed are various embodiments for disabling administrative access to computing resources. A customer request is obtained to disable administrative access of a provider to one or more computing devices. The provider supplies computing resources of the at least one computing device to the customer. The administrative access of the provider to the computing devices is disabled in response to the request. The administrative access of the provider remains disabled until a reset of the computing devices is performed.