Reference Architecture Patterns for Cloud Permission Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Role-based access and permission control systems create complexity and inefficiency in cloud computing environments, making it difficult to manage access for entities involved in the development, deployment, and operation of applications, particularly for sensitive data like financial data.

Innovation Solution

A permissions management system based on reference architecture patterns, where roles and permissions are defined and automatically assigned using blueprints, cookbooks, and templates, allowing for standardized permission management across multiple applications and tiers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional role-based access control systems are used in cloud computing environments, then security control is provided, but system complexity and management inefficiency increase significantly

Engineering Contradiction:
Improvesecurity controlVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies universality by creating reference architecture patterns that can be reused across multiple applications and cloud services. Instead of defining custom roles for each application, a single set of reference roles and permission templates serves multiple purposes across different application types (e.g., SaaS, PaaS, IaaS), reducing overall system complexity while maintaining security control.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent implements preliminary action by pre-defining reference architecture patterns, reference roles, and permission templates before actual application deployment. These reference configurations are prepared in advance and can be automatically assigned to applications, eliminating the need for complex custom role definitions at deployment time and reducing management overhead.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If customized roles and permissions are defined for each application and entity, then specific access control requirements are met, but management time and operational overhead increase

Engineering Contradiction:
Improveaccess control accuracyVSAvoidmanagement time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent uses copying by creating reference architecture patterns that serve as templates for multiple applications. Instead of defining roles from scratch for each application, the system copies and adapts proven reference patterns (e.g., developer roles, administrator roles, operator roles) to new applications, significantly reducing the time and effort required for access control configuration while maintaining appropriate security boundaries.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The reference roles and permission templates are designed to be universally applicable across different application types and cloud service models. A single reference role definition can serve multiple applications simultaneously, allowing one-time configuration that provides ongoing access control for numerous entities without requiring repeated customization efforts.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If traditional permission management systems are used, then access control is provided, but automation capability and efficiency are reduced

Engineering Contradiction:
Improveaccess controlVSAvoidautomation capability
Core Design Contradiction:
ReliabilityVSExtent of automation

Solution Approach 1:

The patent implements self-service by enabling applications and entities to automatically receive appropriate permissions based on their association with reference architecture patterns. The system automatically matches applications to reference patterns, assigns reference roles, and configures permissions without requiring manual intervention from security administrators, thereby enhancing automation capability while maintaining reliable access control.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system incorporates feedback mechanisms that monitor application characteristics, usage patterns, and security requirements to dynamically adjust permission assignments. The reference architecture patterns include feedback loops that automatically update role definitions and permission templates based on observed system behavior and security events, enabling automated adaptation and improvement of access control policies.

Inventive Principle:
Principle #23Feedback

Data Source

PatentEP3424197B1Method and system for providing permissions management
Publication Date: 2021.10.06 INTUIT INC
  • EP3424197B1 patent drawingFigure 1
  • EP3424197B1 patent drawingFigure 2
  • EP3424197B1 patent drawingFigure 3

AI summary

Reference architecture pattern role data representing reference architecture pattern roles to be associated with entities taking part in the development, and/or deployment, and/or operation of an application is generated. Reference architecture pattern tier data representing reference architecture pattern tiers used to create, and/or deploy, and/or operate an application using the reference architecture pattern is generated. For each reference architecture pattern role at least one access and/or operational permission is associated with each reference architecture pattern tier. An entity is assigned one of the reference architecture pattern roles and for each reference architecture pattern tier, the entity is automatically provided the at least one access and/or operational permission associated with the reference architecture pattern role assigned to the entity. When a computing task is requested, permissions associated with the computing task are adjusted based on a risk level associated with performance of the requested computing task.