- 专利标题: Cloud least identity privilege and data access framework
-
申请号: US16919800申请日: 2020-07-02
-
公开(公告)号: US20200336489A1公开(公告)日: 2020-10-22
- 发明人: Ben A. Wuest , William A. Bird , Brad J. Peters , Dasharath P. Chavda , Gregory A. Davis
- 申请人: Sonrai Security Inc.
- 申请人地址: US NY New York
- 专利权人: Sonrai Security Inc.
- 当前专利权人: Sonrai Security Inc.
- 当前专利权人地址: US NY New York
- 主分类号: H04L29/06
- IPC分类号: H04L29/06
摘要:
A network-accessible service provides an enterprise with a view of identity and data activity in the enterprise's cloud accounts. The service enables distinct cloud provider management models to be normalized with centralized analytics and views across large numbers of cloud accounts. Using a domain-specific query language, the system enables rapid interrogation of a complete and centralized data model of all data and identity relationships. The data model also supports a cloud “least privilege and access” framework. Least privilege is a set of minimum permissions that are associated to a given identity; least access is a minimal set of persons that need to have access to given piece data. The framework maps an identity to one or more actions collected in cloud audit logs, and dynamically-build a compete view of an identity's effective permissions. The resulting least privilege and access policies are then applied natively to a given cloud environment to manage access.
公开/授权文献
- US11134085B2 Cloud least identity privilege and data access framework 公开/授权日:2021-09-28
信息查询