Token Renewal Mechanism for Cloud Resource Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In cloud computing environments, resources often face challenges in interacting with each other due to different security domains and lack of access control over underlying infrastructure, leading to limitations in access management and potential security risks.

Innovation Solution

A token renewal mechanism and stacked identifiers are introduced to enable resource principals to periodically re-attest and extend access duration, while also limiting the exposure window for compromised credentials, allowing resources to interact securely across different security domains.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Duration of action of stationary object

If resources are granted long-lived access to interact across different security domains, then access duration is improved, but security risk increases due to potential credential compromise

Engineering Contradiction:
Improveaccess durationVSAvoidsecurity risk
Core Design Contradiction:
Duration of action of stationary objectVSObject-affected harmful factors

Solution Approach 1:

The patent implements periodic credential rotation where resource principals must re-authenticate at scheduled intervals. The access control system rotates credentials periodically, forcing resources to re-prove their identity and authorization. This periodic action maintains long access duration while periodically resetting security exposure windows, resolving the contradiction between prolonged access and security risk.

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The system changes the temporal parameter of credential validity by implementing time-varying access rights. Instead of static long-lived credentials, the system uses time-limited credentials that automatically expire or require renewal. This parameter change allows the system to provide long-term access capability while limiting the actual exposure window of any single credential, balancing access duration and security risk.

Inventive Principle:
Principle #35Parameter changes

2Manufacturing precision

If multiple credentials are maintained for different security domains, then access control precision is improved, but device complexity increases

Engineering Contradiction:
Improveaccess control precisionVSAvoidcredential management complexity
Core Design Contradiction:
Manufacturing precisionVSDevice complexity

Solution Approach 1:

The patent introduces a universal access control system that handles multiple security domains through a single integrated framework. Instead of maintaining separate credential systems for different domains, the system uses a unified mechanism that can issue and manage credentials across various security boundaries. This multi-functional approach maintains access control precision while reducing the operational complexity of managing multiple credential systems.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The access control system acts as an intermediary between resource principals and protected resources. Rather than requiring resources to directly manage multiple domain-specific credentials, the intermediary system centralizes credential issuance, validation, and rotation. This mediator approach maintains precise access control for different security domains while significantly reducing the complexity burden on individual resources.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If resources must frequently re-attest to maintain access, then security is improved, but operational overhead increases

Engineering Contradiction:
ImprovesecurityVSAvoidoperational efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system performs preliminary credential issuance and configuration when resources are first granted access. By pre-establishing the access framework, policies, and initial credentials, the system reduces the operational overhead of subsequent re-attests. The preliminary setup includes configuring automatic renewal mechanisms and pre-validating access paths, so that periodic re-attests become simpler and faster operations.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The access control system implements feedback mechanisms that monitor resource behavior and security conditions. Based on this feedback, the system can dynamically adjust the frequency and strictness of re-attests. For trusted resources with stable access patterns, the system can reduce re-attestation frequency, while maintaining security for resources showing suspicious behavior. This feedback-driven approach balances security requirements with operational efficiency.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11418343B2Access control for long-lived resource principals
Publication Date: 2022.08.16 ORACLE INT CORP
  • US11418343B2 patent drawing
  • US11418343B2 patent drawing
  • US11418343B2 patent drawing

AI summary

Techniques are described for enabling resources within a cloud computing system to interact with each other. In certain embodiments, a token renewal mechanism is provided for extending the duration in which a first resource can access another resource. The token renewal mechanism can involve the first resource periodically causing a new credential to be generated for itself and then communicating the new credential to an identity and access management (IAM) system. The new credential may be generated for compliance with a credential rotation policy specifying that credentials should be changed after a certain period of time. The IAM system may associate a digital access token with the new credential so that for subsequent requests, the IAM system will only recognize the resource principal based upon the new credential. The digital token can be invalidated if a new credential is not changed within the specified period of time.