Invention Grant
- Patent Title: Analysis of role reachability using policy complements
-
Application No.: US17119868Application Date: 2020-12-11
-
Publication No.: US11757886B2Publication Date: 2023-09-12
- Inventor: John Byron Cook , Neha Rungta , Carsten Varming , Daniel George Peebles , Daniel Kroening , Alejandro Naser Pastoriza
- Applicant: Amazon Technologies, Inc.
- Applicant Address: US WA Seattle
- Assignee: Amazon Technologies, Inc.
- Current Assignee: Amazon Technologies, Inc.
- Current Assignee Address: US WA Seattle
- Agency: Kowert, Hood, Munyon, Rankin & Goetzel, P.C.
- Agent Robert C. Kowert
- Priority: ES 202031234 2020.12.10
- Main IPC: H04L9/40
- IPC: H04L9/40 ; H04L41/0604 ; H04L41/22 ; G06F21/62 ; G06F16/901

Abstract:
Methods, systems, and computer-readable media for analysis of role reachability using policy complements are disclosed. An access control analyzer determines two nodes in a graph that potentially have a common edge. The nodes correspond to roles in a provider network, and the roles are associated with first and second access control policies that grant or deny access to resources. The access control analyzer performs a role reachability analysis that determines whether the first role can assume the second role for a particular state of one or more key-value tags. The role reachability analysis determines a third access control policy authorizing a negation of a role assumption request for the second role. The role reachability analysis performs analysis of the third access control policy with respect to a role assumption policy for the second role for the particular state of the one or more key-value tags.
Public/Granted literature
- US20220191206A1 ANALYSIS OF ROLE REACHABILITY USING POLICY COMPLEMENTS Public/Granted day:2022-06-16
Information query