Privilege Revocation Service for Cloud Computing Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Customers who utilize computing resources from a provider entity face challenges in disabling administrative access to maintain privacy, prevent unauthorized access, and ensure compliance, as existing systems lack robust mechanisms to revoke administrative privileges without allowing regaining access by the provider entity.
Innovation Solution
The implementation of a privilege revocation service that restricts administrative access to computing devices, allowing customers to disable administrative privileges, which can only be regained through interrupting the operation of the computing device, such as a hardware or software reset, ensuring secure and controlled access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If administrative access is maintained for infrastructure maintenance and support, then system reliability and operational capability are improved, but security risk and unauthorized access increase
Solution Approach 1:
The patent segments administrative access into two distinct states: enabled state for infrastructure maintenance and disabled state for customer data privacy. The privilege revocation service implements this segmentation by allowing customers to selectively disable administrative privileges while maintaining the ability to re-enable them through controlled reset mechanisms, thus resolving the contradiction between operational capability and security risk
Solution Approach 2:
The patent implements dynamic administrative access control where the access state can change based on customer requests and system conditions. The privilege revocation service dynamically adjusts administrative privileges by processing customer requests to disable/enable access, and automatically restores access after device resets, making the system adaptable to different security and operational requirements
2Object-affected harmful factors
If administrative privileges are disabled to prevent unauthorized access, then security and data privacy are improved, but system maintainability and administrative support capability deteriorate
Solution Approach 1:
The patent applies preliminary action by implementing a privilege revocation service that proactively disables administrative privileges before potential unauthorized access occurs. The service is configured to automatically restore administrative access after device resets, ensuring that the system maintains security while preserving maintainability through automated privilege restoration
Solution Approach 2:
The privilege revocation service acts as an intermediary between customer security requirements and infrastructure maintenance needs. It mediates the contradiction by implementing a layered access control mechanism that allows customers to disable administrative access for security while the service itself maintains the capability to restore access for legitimate maintenance operations through reset mechanisms
3Productivity
If administrative access is continuously enabled for support tasks, then operational efficiency is improved, but compliance with data privacy and legal requirements deteriorates
Solution Approach 1:
The patent implements periodic action through the automated restoration of administrative privileges after device resets. The privilege revocation service periodically checks and restores access rights, ensuring that administrative capabilities are temporarily suspended for compliance but automatically restored when needed for operational efficiency, thus balancing compliance and productivity
Data Source
AI summary
Disclosed are various embodiments for disabling administrative access to computing resources. A customer request is obtained to disable administrative access of a provider to one or more computing devices. The provider supplies computing resources of the at least one computing device to the customer. The administrative access of the provider to the computing devices is disabled in response to the request. The administrative access of the provider remains disabled until a reset of the computing devices is performed.


