Unified Trust Platform for Multi-Cloud Ephemeral Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Managing access and security across multi-cloud environments is challenging due to the complexity of provisioning cloud services, lack of timely visibility into security and compliance, and the need for multiple cybersecurity tools, leading to data breaches and skill shortages.

Innovation Solution

A trust platform that provides a unified view of security and compliance across multiple clouds, offering ephemeral just-in-time access management, policy-driven control generation, and consolidated security and compliance controls, utilizing APIs to manage cloud assets and reduce the attack surface by creating temporary user accounts and automating security and compliance deployments.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If traditional cloud service provisioning methods are used in multi-cloud environments, then each cloud provider's services can be accessed, but the complexity of managing access and security increases significantly

Engineering Contradiction:
Improvemulti-cloud service accessVSAvoidaccess management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent merges multiple cloud service access points into a single unified access portal. The system consolidates authentication, authorization, and credential management across multiple cloud providers (AWS, Azure, GCP, etc.) into one centralized interface, allowing users to access diverse cloud services without managing separate access mechanisms for each provider.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The access management system is designed with universal functionality to handle multiple cloud providers and service types through a single platform. It provides multi-cloud support, unified authentication, temporary credential generation, and security policy enforcement that works across different cloud environments, eliminating the need for provider-specific management tools.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Ease of operation

If permanent user accounts are created for cloud asset access, then continuous access is enabled, but the attack surface increases and security risks rise

Engineering Contradiction:
Improvecontinuous accessVSAvoidattack surface
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system replaces static permanent accounts with dynamic temporary credentials that are automatically generated, time-limited, and purpose-specific. Access credentials have defined start and end times, and are revoked automatically after use or when no longer needed, creating a dynamic access model that adapts to actual usage patterns rather than maintaining perpetual access rights.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent implements disposable temporary access credentials that are created on-demand for specific tasks and automatically destroyed after use or expiration. These short-lived credentials minimize the attack surface because they cannot be reused after expiration and are revoked immediately when no longer needed, unlike permanent accounts that remain valid indefinitely.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

3Reliability

If multiple cybersecurity tools are deployed to manage security across multi-cloud environments, then comprehensive security coverage is achieved, but the complexity of deployment and management increases

Engineering Contradiction:
Improvesecurity coverageVSAvoidtool deployment complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system combines multiple cybersecurity functions (authentication, authorization, credential management, policy enforcement, monitoring) into a single unified access management platform. This consolidation provides comprehensive security coverage across multi-cloud environments while eliminating the need to deploy and manage separate tools for each security function.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The access management system provides universal security controls that work across multiple cloud providers through a single platform. It implements unified authentication, authorization policies, and credential management that are applicable to AWS, Azure, GCP, and other cloud services, replacing the need for provider-specific security tools.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Extent of automation

If manual security and compliance management is performed across multi-cloud environments, then detailed control is maintained, but time consumption and resource requirements increase

Engineering Contradiction:
Improvemanual control capabilityVSAvoidsecurity management time
Core Design Contradiction:
Extent of automationVSLoss of time

Solution Approach 1:

The system implements automated self-service capabilities where temporary credentials are automatically generated, distributed, and revoked based on predefined policies and actual usage needs. Security and compliance controls are automatically enforced through policy-based management, eliminating the need for manual intervention in credential provisioning and security monitoring while maintaining detailed control.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary configuration of security policies, access rules, and compliance requirements before actual cloud asset access occurs. By pre-defining authorization policies, credential lifecycles, and security parameters, the system automates the enforcement of these controls in real-time without requiring manual security management during operations.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11431697B2Access management for multi-cloud workloads
Publication Date: 2022.08.30 EMC IP HLDG CO LLC
  • US11431697B2 patent drawing
  • US11431697B2 patent drawing
  • US11431697B2 patent drawing

AI summary

An apparatus comprises a processing device configured to receive, at a user interface of a trust platform configured to manage cloud assets operating in clouds of multiple cloud service providers, a request by a user to access a given cloud asset on which one or more workloads of a given entity run. The processing device is also configured to generate, on the given cloud asset utilizing application programming interfaces of the trust platform, a temporary user account responsive to determining that the requesting user is registered with the trust platform as an authorized user for the given entity and the given asset. The processing device is further configured to provide access credentials for the temporary user account to the requesting user, to monitor use of the temporary user account, and to remove the temporary user account from the given cloud asset based at least in part on the monitored use.