Temporary Cloud Credentials for Genomic Data Sharing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems face challenges in securely and efficiently sharing genomic data among diverse parties due to technical, security, legal, and financial constraints, leading to fragmented data silos and limited collaboration.

Innovation Solution

A cloud-based platform that implements policy-based access control to orchestrate secure access to genomic digital data resources, using limited temporary derived credentials and signed access tokens to manage access and ensure compliance with sharing policies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If cloud provider credentials are made accessible to multiple tenants for genomic data sharing, then data collaboration and access flexibility improve, but security risks and credential management complexity increase

Engineering Contradiction:
Improvedata sharing flexibilityVSAvoidsecurity risk
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent replaces permanent cloud provider credentials with temporary derived credentials that have limited validity periods. These temporary credentials are generated on-demand and automatically expire, eliminating the security risks associated with long-lived credentials while maintaining the ability for multiple tenants to access genomic data resources.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Solution Approach 2:

The patent introduces a credentials management service as an intermediary between tenants and cloud provider resources. This service acts as a mediator that issues temporary derived credentials to tenants based on policy-based access control definitions, thereby controlling access without requiring tenants to manage their own permanent credentials.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Duration of action of stationary object

If permanent cloud provider credentials are used for multi-tenant access, then access continuity is maintained, but credential rotation and security updates become difficult

Engineering Contradiction:
Improveaccess continuityVSAvoidcredential rotation
Core Design Contradiction:
Duration of action of stationary objectVSEase of manufacture

Solution Approach 1:

The patent transitions from static permanent credentials to dynamic temporary credentials that can be generated, rotated, and expired automatically. The credentials management service dynamically issues new temporary credentials when needed and revokes old ones, enabling continuous access without manual credential rotation while maintaining security through automatic updates.

Inventive Principle:
Principle #15Dynamics

3Reliability

If policy-based access control is implemented for genomic data sharing, then data security and compliance improve, but access management complexity increases

Engineering Contradiction:
Improvedata securityVSAvoidaccess management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements policy-based access control where access rules are defined in advance before data sharing occurs. The credentials management service pre-configures policy definitions that automatically determine which tenants can access which resources, eliminating the need for manual access management decisions while maintaining strong security and compliance controls.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12238102B2Temporary cloud provider credentials via secure discovery framework
Publication Date: 2025.02.25 ILLUMINA INC
  • US12238102B2 patent drawing
  • US12238102B2 patent drawing
  • US12238102B2 patent drawing

AI summary

Cloud provider accounts can be integrated into a software-as-a-service platform. Configuration options can be provided to support various levels of granularity so that different cloud provider accounts can be provided to different tenants, workgroups, users, applications, and the like. From a user perspective, the fact that data is being stored at a cloud provider account can be transparent in that the same features and authentication process can be supported across different cloud provider types. In practice, limited temporary derived credentials can be generated from underlying credentials to provide fine-grained control of access to cloud provider account resources while avoiding administrative overhead.