Cloud Access Entity for Multi-Tenant Permission Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current cloud-based management systems lack efficient methods for managing access permissions and facilitating requests for cloud-based service instances across multi-tenant computing clouds, leading to potential security risks and inefficiencies in resource allocation.
Innovation Solution
A cloud management service that communicates with multi-tenant computing clouds to establish and manage cloud-based service instances, including creating access entities with specific permissions, authenticating requests, and enabling authorized actions using access credentials, while ensuring secure access control and efficient resource utilization.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a multi-tenant cloud computing service provider allows customers to instantiate virtual servers without requiring ownership or management of underlying hardware, then ease of operation is improved, but device complexity increases due to the need for sophisticated access control mechanisms
Solution Approach 1:
The patent introduces an access entity as an intermediary between the customer and the cloud service provider's infrastructure. This access entity serves as a mediator that handles authentication and authorization, allowing customers to access virtual servers without directly managing underlying hardware while maintaining security. The access entity acts as a credential-bearing intermediary that simplifies the customer's interaction complexity.
Solution Approach 2:
The patent segments the access control system into distinct components: access entities, credentials, and authorization mechanisms. By dividing the authentication and authorization functions into separate manageable segments, the system reduces operational complexity for customers while maintaining robust security controls over the underlying hardware infrastructure.
2Reliability
If access controls are implemented to determine if requests are allowable, then security is improved, but productivity decreases due to additional authentication and authorization steps
Solution Approach 1:
The patent implements preliminary authentication by establishing access entities and issuing credentials before customers interact with cloud services. This preliminary action ensures that security verification is completed in advance, allowing subsequent requests to be processed more efficiently without repeated authentication overhead, thus maintaining security while improving productivity.
Solution Approach 2:
The access entity enables self-service authentication and authorization for customers. Once credentials are issued, customers can independently verify their own access rights and make authorized requests without requiring manual security checks, thereby maintaining strong security controls while reducing the productivity impact of authentication steps.
3Reliability
If access entities with specific permissions are created for each cloud service instance, then reliability is improved through enhanced access control, but device complexity increases due to multiple access entities and credentials to manage
Solution Approach 1:
The patent creates access entities that serve multiple functions: authentication, authorization, and credential management. Each access entity is designed to be multi-functional, handling various security operations across different cloud service instances. This universality reduces the need for separate access control mechanisms for each service, thereby maintaining reliability while reducing overall system complexity.
Data Source
AI summary
A method and system for facilitating management of cloud-based service instances, the system including one or more computing systems configured to communicate with at least one multi-tenant computing cloud, and configured to establish a cloud-based service instance hosted in the multi-tenant computing cloud and an access entity with permissions to access the established cloud-based service instance. The system can receive a request for the cloud-based service instance, the request authenticated as originating from a requestor; consult a set of access controls associated with the cloud-based service instance; determine, responsive to the consulting, if the request is allowable by the requestor; and enable, responsive to determining that the request is allowable by the requestor, the requestor to complete the request using a restricted access credential associated with the access entity.


