Social Graph-Based Cloud Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems for controlling access to cloud-based services lack dynamic and granular control mechanisms, failing to effectively manage access based on social network associations, which limits flexibility and security in managing user permissions.

Innovation Solution

A system that includes a controller, authentication module, and permission module to receive access requests, authenticate users, determine social network associations, and generate access permission data based on predefined access settings, allowing or denying access to cloud-based services based on these associations, thereby enabling dynamic and granular access control.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If traditional access control systems are used to manage cloud-based service access, then access management is straightforward and secure, but the system lacks dynamic control capabilities and cannot adapt to social network associations

Engineering Contradiction:
Improvedynamic access control capabilityVSAvoidaccess control system complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The access control system transitions from static permission settings to dynamic control by continuously monitoring social network associations. Access permissions are automatically adjusted based on real-time social graph data, allowing the system to adapt to changing relationships between users and the service administrator without manual intervention.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

A social graph database serves as an intermediary layer between the access control system and users. This intermediary stores and manages social network associations, enabling the system to query and respond to relationship-based access requests without directly implementing complex social networking logic in the access control module.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Extent of automation

If manual access permission management is implemented, then security control is precise, but the system lacks automation and requires continuous administrative intervention

Engineering Contradiction:
Improveautomatic access controlVSAvoidaccess permission security
Core Design Contradiction:
Extent of automationVSReliability

Solution Approach 1:

The system implements continuous feedback loops by monitoring social network graph changes and automatically responding to update access permissions. When social associations change (new friends, removed connections), the system receives feedback and automatically adjusts access rights, maintaining security without requiring manual verification of each change.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The access control system performs self-service by automatically managing permission updates based on social network data. The system autonomously grants or revokes access rights when social associations change, eliminating the need for manual administrative intervention while maintaining consistent security policies defined by the service administrator.

Inventive Principle:
Principle #25Self-service

3Ease of operation

If granular access control based on social associations is implemented, then flexibility in managing different user groups is improved, but the system complexity and computational requirements increase

Engineering Contradiction:
Improveuser permission management easeVSAvoidpermission module complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The system segments access control into distinct modules: social graph management, association detection, permission evaluation, and access decision-making. Each module handles a specific aspect of social-based access control, making the overall complex system manageable through clear separation of concerns and independent optimization of each component.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The access control system implements universal permission templates that can be applied to different social association types (friends, family, colleagues). A single permission setting can govern access for multiple user groups simultaneously, reducing the operational complexity of managing granular permissions across diverse social relationships.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS8819851B1Access control using social network associations
Publication Date: 2014.08.26 GOOGLE LLC
  • US8819851B1 patent drawing
  • US8819851B1 patent drawing
  • US8819851B1 patent drawing

AI summary

The disclosure includes a system and method for performing access control. The system includes a controller, an authentication module and a permission module. The controller receives an access request from a first user. The access request indicates a request to access a cloud-based service managed by a second user. The authentication module authenticates the first user. The permission module determines a first social network association that exists between the first user and the second user based at least in part on a social graph and determines whether access to the cloud-based service is permitted for the first social network association based at least in part on an access setting of the cloud-based service. Responsive to determining that the access is permitted for the first social network association, the permission module generates access permission data to permit the first user to access the cloud-based service.