Invention Grant
- Patent Title: Cloud least identity privilege and data access framework
-
Application No.: US17487124Application Date: 2021-09-28
-
Publication No.: US12021873B2Publication Date: 2024-06-25
- Inventor: Ben A. Wuest , Willam A. Bird , Brad J. Peters , Dasharath P. Chavda , Gregory A. Davis
- Applicant: Sonrai Security Inc.
- Applicant Address: US NY New York
- Assignee: Sonrai Security Inc.
- Current Assignee: Sonrai Security Inc.
- Current Assignee Address: US NY New York
- Agent David H. Judson
- Main IPC: H04L9/40
- IPC: H04L9/40 ; G06F21/45 ; G06F21/62

Abstract:
A network-accessible service provides an enterprise with a view of identity and data activity in the enterprise's cloud accounts. The service enables distinct cloud provider management models to be normalized with centralized analytics and views across large numbers of cloud accounts. Using a domain-specific query language, the system enables rapid interrogation of a complete and centralized data model of all data and identity relationships. The data model also supports a cloud “least privilege and access” framework. Least privilege is a set of minimum permissions that are associated to a given identity; least access is a minimal set of persons that need to have access to given piece data. The framework maps an identity to one or more actions collected in cloud audit logs, and dynamically-build a compete view of an identity's effective permissions. The resulting least privilege and access policies are then applied natively to a given cloud environment to manage access.
Public/Granted literature
- US20230110220A1 Cloud least identity privilege and data access framework Public/Granted day:2023-04-13
Information query