Remote Principal Objects for Secure External Identity Authorization
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for secure resource authorization for external identities lack efficient mechanisms to manage access permissions and lifecycle governance, leading to potential security risks and administrative complexities in multi-domain scenarios.
Innovation Solution
The implementation of remote principal objects (RPOs) that allow external entities to define permissions and access policies immutably, with an entitlements lifecycle manager (ELM) service governing access, ensuring secure and controlled access to data resources across domains.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the data resource owner defines and manages permissions for external identities directly in their directory, then the owner has full control over access permissions and can alter types of accesses allowed, but this creates administrative complexity and security risks when managing access across multiple domains
Solution Approach 1:
The patent introduces remote principal objects (RPOs) as intermediary entities that mediate between external identities and data resources. RPOs are created in the owner's directory but represent external principals, allowing permission management without direct owner intervention for each access request. The entitlements lifecycle manager (ELM) service acts as another intermediary that automatically governs the lifecycle of RPOs, including creation, activation, and deletion based on access requests and approvals, thereby reducing administrative complexity while maintaining security control.
2Ease of operation
If traditional guest credential implementations are used with owner directory entries having limited permissions, then access is granted to external identities, but the owner must manually manage and alter permissions which increases administrative overhead
Solution Approach 1:
The system enables self-service access management where external identities can request access to data resources through the user interface without requiring manual permission configuration by the owner. The ELM service automatically processes these requests, creates RPOs, and manages the entitlements lifecycle. The owner only needs to provide initial approval for access templates, after which the system autonomously handles permission grants, modifications, and revocations based on predefined policies and access requests.
3Reliability
If manual permission management is implemented for each external identity, then precise access control is achieved, but tracking and managing individual access grants becomes increasingly complex as the number of external identities grows
Solution Approach 1:
The patent merges multiple external identities with similar access requirements into groups, where a single RPO can represent multiple principals. The ELM service manages entitlements at the group level rather than individual identity level, significantly reducing the number of RPOs that need to be tracked. Access templates define permissions for groups of external identities collectively, allowing precise access control to be maintained while dramatically simplifying the tracking and management overhead as the system scales to accommodate more external identities.
Data Source
AI summary
Methods of secure resource authorization for external identities using remote principal objects are performed by systems and devices. An external entity creates a user group and defines entitlements to an owning entity's secure resource as a set of permissions for the group. An immutable access template with the permissions and an access policy for the secure resource are provided to the owning entity for approval. On approval, a remote principal object is created in the owner directory according to the permissions and access policy. A remote principal that is a group member requests access via an interface to the owner domain using external domain credentials. The identity of the remote principal is verified against the remote principal object by a token service. Verification causes generation and issuance of a token, with the enumerated entitlements, to the remote principal interface affecting a redirect for access to the secure resource.


