Role-Based Permission Delegation for Least-Privilege Provider Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing provider networks face challenges in efficiently managing role-based permission delegation while adhering to the principle of least privilege, leading to potential misuse of permissions and increased resource consumption.

Innovation Solution

A system and method for role-based permission delegation in provider networks that allows a delegating service to grant a strict subset of actions to an assuming service, using a down scoping policy to ensure the assuming service operates within the limits of the customer's permissions, thereby adhering to the principle of least privilege.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If a service is granted broad permissions to perform actions on customer resources, then the service can perform more actions efficiently, but the principle of least privilege is violated and security risks increase

Engineering Contradiction:
Improveservice action efficiencyVSAvoidpermission security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent segments permissions into hierarchical levels: customer roles define the complete set of actions, delegation roles define subsets of those actions, and assuming services receive only the specific subset needed. This segmentation allows services to operate efficiently with minimal necessary permissions while maintaining security through the principle of least privilege.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies local quality by allowing different services to have different permission scopes tailored to their specific needs. Each assuming service receives a customized subset of actions relevant to its function, rather than uniform broad or narrow permissions across all services. This enables each service to operate with optimal efficiency for its specific tasks while maintaining overall security.

Inventive Principle:
Principle #3Local quality

2Reliability

If a service is granted limited permissions to adhere to the principle of least privilege, then security is improved, but the service cannot perform all necessary actions efficiently

Engineering Contradiction:
Improvepermission securityVSAvoidservice action efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent introduces delegation roles as intermediaries between customer roles and assuming services. The delegation role acts as a mediator that receives broad permissions from the customer role and selectively delegates specific subsets to assuming services. This intermediary structure enables assuming services to receive precisely the permissions they need for efficient operation without requiring them to have direct access to broad customer role permissions.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If a delegating service manages permission delegation manually, then flexibility is maintained, but administrative complexity and costs increase

Engineering Contradiction:
Improvepermission management flexibilityVSAvoidadministrative complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements self-service through automated assumption role mechanisms where assuming services can autonomously request and receive appropriate permission subsets from delegation roles based on their operational needs. The system automatically manages the delegation process, reducing manual administrative intervention while maintaining flexibility. The automated workflows handle permission allocation, tracking, and revocation based on service requirements and policy rules.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12438872B2Role-based permission delegation in a provider network
Publication Date: 2025.10.07 AMAZON TECH INC
  • US12438872B2 patent drawing
  • US12438872B2 patent drawing
  • US12438872B2 patent drawing

AI summary

Techniques for role-based permission delegation in a provider network. The techniques include an assuming service in the provider network sending a request to a temporary credential service in the provider network to assume a delegation role. The assuming service, acting in the delegation role, sending a request to the temporary credential service to assume the customer role in accordance with a down scoping policy. The assuming service, acting in the customer role, performing an action in a strict subset of actions on a customer resource. The techniques improve the operation of the provider network by allowing a permission to perform an action on the customer resource that is granted by the customer to a delegating service in the provider network to be delegated to the assuming service while complying with the access control principle of least privilege.