Quorum-Based Authorization for Remote Access to Sensitive Cloud Assets

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cloud migration solutions do not effectively address the challenge of authenticating multiple users simultaneously for secure access to sensitive cloud assets, particularly in scenarios requiring physical isolation and remote accessibility.

Innovation Solution

A system and method for quorum-based authentication that involves a user device, service provider, and identity provider, where a device app determines quorum approval from multiple authorizers before granting temporary access to cloud resources, enforcing temporal and physical constraints.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional single-user authentication is used, then access is simple and fast, but security is insufficient for sensitive cloud assets

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication process is segmented into multiple independent authorizer components, where each authorizer evaluates and votes on the access request separately. This segmentation allows the system to achieve high security through multiple checks while maintaining manageable complexity by treating each authorizer as an independent unit that can be configured and managed separately.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary quorum authentication mechanism that mediates between multiple authorizers and the final access decision. This intermediary layer collects votes from multiple authorizers, applies quorum logic, and produces a unified authentication result, thereby simplifying the overall system architecture while ensuring high security through distributed authorization.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If multiple users must be physically present for authentication, then security is enhanced, but remote accessibility is reduced

Engineering Contradiction:
ImprovesecurityVSAvoidremote accessibility
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent replaces the mechanical requirement of physical presence with an electronic/digital authentication mechanism. Multiple authorizers can cast their votes remotely through electronic channels, and the quorum authentication system processes these electronic inputs to determine access. This substitution eliminates the need for physical co-location while maintaining the security benefits of multi-user authentication.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If continuous access monitoring is implemented, then security control is improved, but system performance decreases

Engineering Contradiction:
Improveaccess controlVSAvoidsystem performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements periodic access monitoring rather than continuous monitoring. The system periodically checks whether the quorum authentication conditions are still satisfied and whether access should be maintained or revoked. This periodic approach provides adequate security control while significantly reducing the performance overhead compared to continuous monitoring, as the system only needs to evaluate authentication status at discrete intervals.

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS12375478B2Quorum-based authorization to secure sensitive cloud assets
Publication Date: 2025.07.29 THALES DIS CPL USA INC
  • US12375478B2 patent drawing
  • US12375478B2 patent drawing
  • US12375478B2 patent drawing

AI summary

Provided is a system and method to authenticate multiple users in order to secure sensitive cloud assets. The system comprises a user device, a service provider, and an identify provider. The service provider provides services for producing and consuming data. The identify provider authenticates and authorizes multiple authorizors for providing user access to the resources and data. A device app communicates with the service provider and identify provider. The device app polls votes and determines when a quorum approval for utilizing data is met within a constraint. It authorizes the user temporary access to the data for use by one of the services upon quorum approval, and enforces temporal and physical conditions on it. The access can be granted via a push action or a pull notification. Other embodiments are disclosed.