Tag-Based Access Control Policies for Cloud Metadata Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional approaches for managing freeform metadata, such as tags, in computing resources lack effective control mechanisms, leading to potential security breaches and inefficient access management in multitenant environments like cloud computing, where users can inadvertently gain access to resources by freely modifying tags.

Innovation Solution

Implementing a system that allows users to assign freeform metadata tags to computing resources, which are then referenced in access control policies to grant or deny permissions, while restricting tag modifications through access control lists and policies based on specific keys and values, ensuring secure and controlled access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If users are allowed to freely modify tags on computing resources, then the flexibility and ease of operation are improved, but security risks and access control reliability deteriorate

Engineering Contradiction:
Improveflexibility in tag assignmentVSAvoidaccess control security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments tag management into two distinct parts: (1) freeform metadata tags for flexible resource identification and categorization, and (2) structured access control tags with defined schemas for security enforcement. This segmentation allows users to freely assign descriptive tags while maintaining controlled access control tags that prevent security breaches.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary access control system that mediates between user requests to modify tags and the actual resource access permissions. The access control policies act as a intermediary layer that evaluates tag modifications against defined rules, allowing flexible tag assignment while maintaining security through policy enforcement.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If access control policies are tightly restricted to prevent security breaches, then security reliability is improved, but flexibility in resource management and ease of operation worsen

Engineering Contradiction:
Improveaccess control securityVSAvoidresource management flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic access control policies that can adapt to different scenarios. The system evaluates access requests in real-time based on the current state of tags and policies, allowing flexible resource management within security boundaries. Policies can be dynamically applied or removed based on tag assignments, enabling versatile resource management while maintaining security.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the parameter of access control from static permission settings to dynamic policy evaluations based on tag attributes. By modifying access control to be parameter-driven (based on tag keys and values), the system achieves both security reliability through enforced policies and flexibility through configurable policy parameters that can adapt to different resource management needs.

Inventive Principle:
Principle #35Parameter changes

3Device complexity

If conventional access control mechanisms are used without tag integration, then system complexity is reduced, but adaptability to modern metadata-driven environments deteriorates

Engineering Contradiction:
Improveaccess control system simplicityVSAvoidcompatibility with metadata environments
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The patent makes the access control system universal by enabling it to work with both traditional resource identification methods and modern tag-based metadata systems. The access control policies can evaluate both conventional access parameters and tag attributes, providing multi-functionality that maintains simplicity for traditional scenarios while adapting to metadata-driven environments.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent creates a conceptual copy of access control functionality that operates at the tag layer without replacing the underlying access control mechanism. By copying access control logic to evaluate tag-based conditions while maintaining the original access control structure, the system achieves adaptability to metadata environments while preserving the simplicity of conventional access control for scenarios where tags are not used.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS10341281B2Access control policies associated with freeform metadata
Publication Date: 2019.07.02 AMAZON TECH INC
  • US10341281B2 patent drawing
  • US10341281B2 patent drawing
  • US10341281B2 patent drawing

AI summary

Approaches are described for security and access control for computing resources. Various embodiments utilize metadata, e.g., tags that can be applied to one or more computing resources (e.g., virtual machines, host computing devices, applications, databases, etc.) to control access to these and/or other computing resources. In various embodiments, the tags and access control policies described herein can be utilized in a multitenant shared resource environment.