Cloud Account Compartments for Granular Access and Cost Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional techniques for managing user access and resource usage in cloud computing environments often result in excessive costs and security risks due to the lack of granular control over user permissions and resource allocation within shared accounts.
Innovation Solution
The implementation of 'compartments' within cloud accounts, which are logical entities that allow for varying levels of access to computing services and resources, enabling better control over user permissions, resource allocation, and billing, with features like tagging for resource tracking, quota management, and the ability to transfer ownership and convert compartments into standalone accounts.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If multiple users share a single cloud account, then resource utilization efficiency improves, but security risks and cost control deteriorate
Solution Approach 1:
The patent divides a cloud account into multiple isolated compartments, each with its own security policies, resource quotas, and billing parameters. This segmentation allows multiple users to share the account while maintaining distinct security boundaries, thus improving resource utilization without compromising security.
2Productivity
If multiple users share a single cloud account, then resource utilization efficiency improves, but cost management deteriorates
Solution Approach 1:
The patent implements compartmentalization that separates cost allocation and billing parameters for different users. Each compartment can have independent billing rules, quotas, and cost centers, enabling precise cost tracking and management while maintaining shared resource utilization.
3Reliability
If individual user accounts are created for each user, then security control improves, but financial burden and system complexity worsen
Solution Approach 1:
The patent merges multiple user environments into a single shared account through isolated compartments. This approach maintains the security control of individual accounts while eliminating the need for separate account management, reducing overall system complexity and financial burden.
4Reliability
If individual user accounts are created for each user, then security control improves, but financial burden worsens
Solution Approach 1:
The patent combines multiple user accounts into a single shared account with isolated compartments, maintaining security control while reducing the financial burden of multiple individual account subscriptions and management overhead.
Data Source
AI summary
Customers of a service provider are able to provision compartments of the accounts. The both the accounts and the compartments, in some embodiments, may have associated computing resources and identities. One or more identities of the account may be authorized to perform administrative operations in the compartment. Identities of the compartment may lack the ability to perform any administrative actions outside of the compartment but inside of the account.


