Surrogate Credentials for Cross-Entity Cloud Resource Authorization
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing cloud computing systems face challenges in efficiently managing access control and authorization across different computing entities, particularly in multi-cloud environments, where separate access policies need to be generated for each entity, leading to complexity and inefficiency.
Innovation Solution
The implementation of surrogate access requests using surrogate tokens and digital signatures allows computing entities to authorize operations on target resources based on access policies associated with a different entity, eliminating the need for separate policy generation and enabling cross-entity authorization.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If separate access policies are generated for each computing entity in multi-cloud environments, then access control security is maintained, but system complexity and management overhead increase significantly
Solution Approach 1:
The patent implements a universal surrogate credential mechanism that can be used across multiple cloud environments and different computing entities. Instead of creating separate access policies for each entity, the system uses a single surrogate credential format that can represent any computing entity's access rights, making the authorization system multi-functional and applicable to diverse cloud scenarios without increasing complexity
Solution Approach 2:
The patent introduces surrogate credentials as an intermediary mechanism between the principal and target resources. These surrogate credentials act as mediators that encapsulate access rights without requiring the principal to directly hold or manage complex access policies. The surrogate credential serves as a simplified representation that the authorization system can verify against existing policies, reducing the complexity of direct policy management while maintaining security
2Reliability
If separate access policies are generated for each computing entity, then entity-specific authorization is ensured, but management time and operational overhead increase
Solution Approach 1:
The patent creates simplified copies of access rights in the form of surrogate credentials. Instead of managing full access policies for each computing entity, the system generates surrogate credentials that copy only the essential access rights needed for specific operations. These credential copies can be quickly issued and verified without requiring the time-consuming process of generating and managing complete access policies for each entity
Solution Approach 2:
The patent performs preliminary authorization by issuing surrogate credentials that pre-encode access rights before the actual resource access occurs. The surrogate credential is generated in advance with the necessary permissions embedded, so that during actual resource access, the authorization system can quickly verify the credential without performing complex real-time policy evaluations, thus reducing management time while ensuring authorization accuracy
3Reliability
If traditional access control methods are used in multi-cloud environments, then security is maintained, but interoperability between different cloud systems is reduced
Solution Approach 1:
The patent designs the surrogate credential mechanism to be universally applicable across different cloud environments. The surrogate credential format and verification process are designed to work with various cloud providers' authorization systems, enabling a single credential to function across multiple cloud platforms. This universal design maintains security through consistent verification while enhancing interoperability by allowing the same credential mechanism to operate in diverse cloud ecosystems
Data Source
AI summary
A system grants access for a computing entity to execute a requested operation upon a target resource based on a set of one or more access policies associated with a different computing entity. The access control service receives a surrogate access request from a first computing entity. The surrogate access request represents a request for the first computing entity to execute a requested operation upon a target resource based on a set of one or more access policies corresponding to a principal associated with a second computing entity. The system obtains a set of one or more access policies respectively, including a set of one or more authorized operations associated with the principal, and determines whether the requested operation corresponds to at least one authorized operation. Responsive to determining that the requested operation corresponds to at least one authorized operation, the system authorizes execution of the requested operation.


