Versioned Access Controls for Workflow Role Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

As data centers grow in scale and complexity, managing and storing increasing amounts of data becomes increasingly costly and complicated, with existing technologies struggling to simplify data storage and management while maintaining efficiency.

Innovation Solution

Implementing versioned and custom access controls within a configurable workflow service that allows for the management of roles and permissions, enabling efficient provisioning and execution of workflows across computing resources, while preserving client expectations and security through role versioning and customization.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Quantity of substance

If data centers grow in scale to store and manage increasing amounts of data, then data storage capacity and management capability are improved, but system complexity and operational costs increase

Engineering Contradiction:
Improvedata storage capacityVSAvoidsystem complexity
Core Design Contradiction:
Quantity of substanceVSDevice complexity

Solution Approach 1:

The patent segments access control management into versioned role definitions, where each role version represents a discrete, manageable unit of permissions. This allows the system to handle complex access control requirements by breaking them down into modular role versions that can be independently managed and assigned to workflows, thereby reducing overall system complexity while maintaining large-scale data management capabilities

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements dynamic role versioning where role definitions can evolve over time through version control. This dynamic approach allows the system to adapt to changing data management requirements without requiring complete restructuring, enabling scalable growth while maintaining manageable complexity through controlled evolution of access control policies

Inventive Principle:
Principle #15Dynamics

2Quantity of substance

If data centers grow in scale to store and manage increasing amounts of data, then data storage capacity is improved, but operational costs increase

Engineering Contradiction:
Improvedata storage capacityVSAvoidoperational costs
Core Design Contradiction:
Quantity of substanceVSLoss of energy

Solution Approach 1:

The patent creates universal role versions that can be reused across multiple workflows and computing resources. By defining roles at a higher level of abstraction that can be instantiated multiple times, the system reduces redundant access control configurations, thereby lowering operational costs while supporting large-scale data storage and management operations

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If versioned access controls are implemented to manage roles and permissions, then security and customization are improved, but system complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by pre-defining role versions with specific permission sets before they are needed for workflow execution. This advance preparation of access control configurations allows the system to maintain high security through carefully crafted role definitions while reducing operational complexity, as roles can be reused without requiring complex runtime decision-making about permissions

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10771586B1Custom access controls
Publication Date: 2020.09.08 AMAZON TECH INC
  • US10771586B1 patent drawing
  • US10771586B1 patent drawing
  • US10771586B1 patent drawing

AI summary

Methods and systems for implementing custom access controls are disclosed. A first task is added to a first workflow. A first role is generated for the first workflow. The first role comprises a first set of one or more permissions for using one or more computing resources. The one or more permissions in the first role are selected based on the first task. The first task is performed using the one or more computing resources in accordance with the first role.