Quorum-Based Access Control Management for Privileged Tasks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing access control systems face challenges in managing complex systems efficiently, requiring secure and fast approval for access control operations, especially for privileged tasks, which often rely on manual intervention from external systems, leading to increased time and security risks.

Innovation Solution

Implementing quorum-based access control management, where a quorum of internal users with high-responsibility roles within the account can approve or deny access control operations, reducing reliance on external systems and enhancing security and speed.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual intervention from external systems is used for access control operations, then security scrutiny is maintained, but resolution time increases and security risks are elevated

Engineering Contradiction:
ImprovesecurityVSAvoidresolution time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent introduces an automated approval system that acts as an intermediary between access control requests and final execution. This system uses pre-configured policies, user roles, and automated workflows to evaluate and approve access requests without requiring manual external intervention, thereby reducing resolution time while maintaining security through structured automated scrutiny

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system enables self-service access control by allowing users to submit access requests and receive automated approvals based on pre-configured policies. The system automatically evaluates requests against security rules, user permissions, and contextual factors, granting access without external manual intervention for routine cases, thus eliminating waiting time while maintaining security through automated policy enforcement

Inventive Principle:
Principle #25Self-service

2Reliability

If manual approval processes are implemented for privileged tasks, then security is enhanced, but operational speed decreases

Engineering Contradiction:
Improvesecurity scrutinyVSAvoidoperational speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements dynamic approval workflows that adapt to the specific context of each access request. For low-risk operations, the system automatically approves requests based on pre-configured policies, while for high-risk privileged tasks, it escalates to multi-factor approval processes. This dynamic adjustment optimizes operational speed for routine tasks while maintaining stringent security scrutiny for sensitive operations

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system applies partial manual intervention only when necessary - using automated approval for routine access control operations and reserving manual external approval only for privileged or high-risk tasks. This selective approach maintains security scrutiny where needed while maximizing operational speed for the majority of routine operations through automation

Inventive Principle:
Principle #16Partial or excessive action

3Reliability

If external system intervention is required for access control operations, then security validation is thorough, but system complexity and coordination overhead increase

Engineering Contradiction:
Improvesecurity validationVSAvoidsystem coordination
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges multiple security validation functions into a single integrated automated approval system. This system consolidates policy evaluation, user permission checking, contextual risk assessment, and approval workflow management into one unified platform, eliminating the need for coordination between multiple external systems while maintaining thorough security validation through integrated checks

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS11914696B1Quorum-based access control management
Publication Date: 2024.02.27 AMAZON TECH INC
  • US11914696B1 patent drawing
  • US11914696B1 patent drawing
  • US11914696B1 patent drawing

AI summary

Quorum-based access control management may be implemented. Quorum controls may be created for determining whether to perform or deny access control operations to perform privileged tasks. When an access control operation is received, approval of the operation may be requested from members for the quorum control. If a policy for the quorum control is satisfied by approval responses, then approval to perform the access control operation may be provided.