Security Role Provisioning for Cloud BLOB Storage
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Enterprise applications face challenges in provisioning and securely accessing BLOB storage on public cloud servers due to compliance issues with enterprise-level security, leading to data silos within the organization.
Innovation Solution
A data store service that generates a security role with specific permissions for tenant services on public servers, using temporary security tokens to control access to data storage containers, allowing granular access control and segregation while enabling sharing among tenant services.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional security policies are implemented for each trust relationship between consumer and producer teams, then security compliance is improved, but data sharing capability deteriorates resulting in data silos
Solution Approach 1:
The patent segments security management by introducing a dedicated security service that handles authentication and authorization independently from data storage and access operations. This segmentation allows security policies to be applied uniformly across different trust relationships without requiring separate policy configurations for each consumer-producer pair, thereby maintaining security compliance while enabling broader data sharing.
Solution Approach 2:
The patent introduces a security service as an intermediary between consumer teams and producer teams. This intermediary manages security tokens, validates access requests, and enforces security policies centrally, eliminating the need for direct trust relationship configurations between each consumer and producer. This intermediary approach resolves the contradiction by maintaining strict security compliance while facilitating seamless data sharing across multiple teams.
2Manufacturing precision
If separate security policies are created for each trust relationship, then access control precision is improved, but system complexity deteriorates
Solution Approach 1:
The patent implements a universal security service that handles multiple functions: authentication, authorization, token generation, and policy enforcement. This single multi-functional component replaces the need for numerous separate security policy configurations for different trust relationships. The security service maintains precise access control by evaluating security rules centrally, while reducing system complexity by consolidating what would otherwise be numerous discrete security management elements.
3Reliability
If enterprise-level security compliance is enforced on public cloud servers, then security reliability is improved, but ease of operation deteriorates
Solution Approach 1:
The patent implements self-service mechanisms where consumer teams can independently provision access to data containers by obtaining security tokens from the security service without requiring manual security policy configurations or administrator intervention. The security service automatically validates requests against security rules and issues appropriate tokens. This self-service approach maintains enterprise-level security compliance while dramatically improving ease of operation by eliminating complex provisioning procedures.
Data Source
AI summary
Systems, devices, and techniques are disclosed for provisioning and secure access control for storage on public servers. Data may be received from a tenant service identifying both the tenant service and a security certificate. A data storage container may be generated on a public server. A security role that is associated with the tenant service and includes permissions for accessing data in the data storage container may be generated on the public server. A request to access the data storage container may be received from the tenant service, including an identification of the tenant service and the security certificate. Credentials and a request to assume the security role may be sent to an identity provider. A temporary security token for accessing the data storage container with the permissions of the security role may be received from the public server. The temporary security token may be sent to the tenant service.


