Hierarchical Account Grouping for Cloud Database Configuration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Managing multiple accounts in cloud-based multi-account database systems is challenging due to the need for manual configuration of account-level resources, leading to repetitive and duplicate work.

Innovation Solution

The introduction of an account group concept, where a parent account group inherits and configures resources for multiple child accounts, simplifying data sharing and access control through higher-level constructs and a control plane.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If manual configuration of account-level resources is performed for each account, then access control and data sharing can be implemented, but repetitive and duplicate work increases and management efficiency decreases

Engineering Contradiction:
ImproveAccount management efficiencyVSAvoidTime spent on repetitive configuration work
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The patent segments account management into hierarchical levels: organization-level (parent) and account-level (child). The parent organization configures resources once at the organizational level, and this configuration is automatically segmented and propagated to multiple child accounts, eliminating repetitive manual configuration work for each individual account.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements preliminary action by allowing the parent organization to pre-configure resource templates, access control policies, and data sharing settings at the organizational level before they are needed at individual account levels. These pre-configured templates are then automatically applied to child accounts, saving time on repetitive configuration tasks.

Inventive Principle:
Principle #10Preliminary action

2Ease of manufacture

If custom solutions or professional services are obtained for multi-account management, then account setup and configuration can be achieved, but costs increase and implementation time is extended

Engineering Contradiction:
ImproveAccount setup capabilityVSAvoidFinancial cost and time investment
Core Design Contradiction:
Ease of manufactureVSQuantity of substance

Solution Approach 1:

The patent enables self-service by providing automated multi-account management capabilities directly within the database system. Organizations can independently configure and manage multiple accounts using the built-in hierarchical structure and automatic propagation features, eliminating the need to hire expensive professional services or develop custom solutions.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent creates a universal account management framework that handles multiple account types, configurations, and use cases through a single unified system. The parent-child hierarchical structure and automatic resource propagation mechanism provide multi-functional capabilities that replace the need for multiple specialized solutions or professional services.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If per-account level configuration is performed for all resources, then precise access control can be implemented, but device complexity and management overhead increase

Engineering Contradiction:
ImproveAccess control precisionVSAvoidConfiguration management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent adds a new hierarchical dimension to account management by introducing the organization-level parent structure above individual account-level children. This dimensional change allows access control policies to be defined once at the parent level and automatically propagated to multiple child accounts, maintaining precise access control while reducing configuration complexity.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Solution Approach 2:

The patent merges the configuration management of multiple child accounts into a single parent organization-level configuration. By combining the management of numerous individual account configurations into one unified parent configuration, the system maintains precise access control across all accounts while significantly reducing the overall complexity of configuration management.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS12277093B2Method for managing a plurality of accounts in a multi-account database system
Publication Date: 2025.04.15 SHANTHARAJ SANDEEP
  • US12277093B2 patent drawing
  • US12277093B2 patent drawing
  • US12277093B2 patent drawing

AI summary

A system for cloud-based data-as-a-service setup and configuration across multiple accounts, multiple regions, and multiple cloud providers, wherein the system uses higher level constructs along with simplified integration of the data-as-a-service accounts with other software products and related analytics. Account group or similar grouping constructs allow for configuring multiple data-as-a-service accounts at once with repetitive and duplicate configuration for each account with the ability to allow for overrides to allow for extensibility or for exception purposes. Logical constructs called namespace allow for grouping resources to create logical boundaries within a shared data-as-a-service account. Namespace provides stored procedures as necessary controls to implement policies as code to keep the namespace behavior consistent. A user interface widget enables specification of privileges that users of a shared data-as-a-service account are allowed to grant and revoke.