Secret Isolation Manager for One-Way Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional access management systems in distributed computing environments are limited in maintaining secret isolation, especially in cross-team or cross-user sharing scenarios, and lack adequate self-service features for secret sharing, leading to risks and manual errors.

Innovation Solution

A secret isolation manager identifies entities as owners of secrets and tags them with one-way affinity identifiers, enabling one-way access control and providing a self-service interface for delegation of access management, allowing secure and efficient secret sharing across teams without manual approvals.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional access management systems are used for secret sharing, then manual approval processes are in place, but this increases processing time and human errors

Engineering Contradiction:
Improvesecret management securityVSAvoidprocessing time for access requests
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements self-service interfaces that enable automated secret sharing between teams without requiring manual approval from the secret management service team. The system automatically processes access requests based on predefined policies and affinity identifiers, eliminating human intervention in the approval process while maintaining security through automated validation mechanisms.

Inventive Principle:
Principle #25Self-service

2Reliability

If manual approval processes are used for secret access, then security control is maintained, but this increases complexity of the access management process

Engineering Contradiction:
Improveaccess control securityVSAvoidaccess management process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system automates access control decisions through self-service interfaces and predefined policies, eliminating the need for manual approval processes. The complexity is reduced by using automated validation based on affinity identifiers and team relationships, while security is maintained through programmatic enforcement of access rules.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent changes the control mechanism from manual approval parameters to automated parameters based on affinity identifiers, team memberships, and predefined policies. This parameter transformation enables the system to make access decisions automatically based on structured data rather than human judgment, reducing process complexity while maintaining security.

Inventive Principle:
Principle #35Parameter changes

3Productivity

If cross-team secret sharing is enabled, then collaboration efficiency is improved, but this risks compromising secret isolation

Engineering Contradiction:
Improvecollaboration efficiencyVSAvoidsecret isolation
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent segments secret access control into distinct affinity identifiers for different teams and contexts. Each secret is tagged with specific affinity identifiers that define which teams can access it. This segmentation enables cross-team sharing for authorized teams while maintaining isolation from unauthorized teams, allowing collaboration efficiency to improve without compromising secret isolation.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system applies different access control qualities to different secrets based on their affinity identifiers. Each secret has its own specific access rules defined by its tags, enabling fine-grained control where cross-team sharing is permitted for some secrets while maintaining strict isolation for others. This local quality approach allows collaboration efficiency to improve for authorized scenarios without compromising overall secret isolation.

Inventive Principle:
Principle #3Local quality

4Extent of automation

If self-service interfaces are implemented for secret management, then automation is improved, but this requires more sophisticated access control mechanisms

Engineering Contradiction:
Improvesecret management automationVSAvoidaccess control mechanism complexity
Core Design Contradiction:
Extent of automationVSDevice complexity

Solution Approach 1:

The patent implements self-service interfaces that automatically manage secret sharing based on predefined policies and affinity identifiers. The automation is achieved by enabling the system to autonomously process access requests without human intervention, using structured data about team relationships and secret tags to make access decisions programmatically.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system transforms access control from manual processes to automated parameter-based decisions. Affinity identifiers and team membership parameters are used to automatically determine access rights, replacing complex manual approval workflows with simpler parameter matching logic. This parameter transformation enables high automation while keeping the underlying mechanism relatively simple.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11356438B2Access management system with a secret isolation manager
Publication Date: 2022.06.07 MICROSOFT TECHNOLOGY LICENSING LLC
  • US11356438B2 patent drawing
  • US11356438B2 patent drawing
  • US11356438B2 patent drawing

AI summary

Methods, systems, and computer storage media for providing identification of secrets as one-way secrets in a computing environment. In particular, a secret isolation manager of an access management in the computing environment can identify an entity as an owner of secrets in a secret storage structure. In operation, the secret isolation manager, can receive a request, associated with a requesting entity, to access a secret associated with an approving entity. The request can be for an application of the requesting entity to access a secret of the approving entity. The secret isolation manager accesses the secret storage structure that stores affinity identifiers, where an affinity identifier indicates that the requesting entity has a one-way affinity with the approving entity that owns the secret. The one-way affinity operates to allow the approving entity to share the secret with the requesting entity, so the requesting entity is granted access to the secret.