Hierarchical Account Grouping for Cloud Database Configuration
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Managing multiple accounts in cloud-based multi-account database systems is challenging due to the need for manual configuration of account-level resources, leading to repetitive and duplicate work.
Innovation Solution
The introduction of an account group concept, where a parent account group inherits and configures resources for multiple child accounts, simplifying data sharing and access control through higher-level constructs and a control plane.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If manual configuration of account-level resources is performed for each account, then access control and data sharing can be implemented, but repetitive and duplicate work increases and management efficiency decreases
Solution Approach 1:
The patent segments account management into hierarchical levels: organization-level (parent) and account-level (child). The parent organization configures resources once at the organizational level, and this configuration is automatically segmented and propagated to multiple child accounts, eliminating repetitive manual configuration work for each individual account.
Solution Approach 2:
The patent implements preliminary action by allowing the parent organization to pre-configure resource templates, access control policies, and data sharing settings at the organizational level before they are needed at individual account levels. These pre-configured templates are then automatically applied to child accounts, saving time on repetitive configuration tasks.
2Ease of manufacture
If custom solutions or professional services are obtained for multi-account management, then account setup and configuration can be achieved, but costs increase and implementation time is extended
Solution Approach 1:
The patent enables self-service by providing automated multi-account management capabilities directly within the database system. Organizations can independently configure and manage multiple accounts using the built-in hierarchical structure and automatic propagation features, eliminating the need to hire expensive professional services or develop custom solutions.
Solution Approach 2:
The patent creates a universal account management framework that handles multiple account types, configurations, and use cases through a single unified system. The parent-child hierarchical structure and automatic resource propagation mechanism provide multi-functional capabilities that replace the need for multiple specialized solutions or professional services.
3Reliability
If per-account level configuration is performed for all resources, then precise access control can be implemented, but device complexity and management overhead increase
Solution Approach 1:
The patent adds a new hierarchical dimension to account management by introducing the organization-level parent structure above individual account-level children. This dimensional change allows access control policies to be defined once at the parent level and automatically propagated to multiple child accounts, maintaining precise access control while reducing configuration complexity.
Solution Approach 2:
The patent merges the configuration management of multiple child accounts into a single parent organization-level configuration. By combining the management of numerous individual account configurations into one unified parent configuration, the system maintains precise access control across all accounts while significantly reducing the overall complexity of configuration management.
Data Source
AI summary
A system for cloud-based data-as-a-service setup and configuration across multiple accounts, multiple regions, and multiple cloud providers, wherein the system uses higher level constructs along with simplified integration of the data-as-a-service accounts with other software products and related analytics. Account group or similar grouping constructs allow for configuring multiple data-as-a-service accounts at once with repetitive and duplicate configuration for each account with the ability to allow for overrides to allow for extensibility or for exception purposes. Logical constructs called namespace allow for grouping resources to create logical boundaries within a shared data-as-a-service account. Namespace provides stored procedures as necessary controls to implement policies as code to keep the namespace behavior consistent. A user interface widget enables specification of privileges that users of a shared data-as-a-service account are allowed to grant and revoke.


