Centralized Cloud Account Mapping Service

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cloud users face challenges in managing and automating the creation of cloud resources due to limitations imposed by cloud providers, such as restrictions on the number of virtual private clouds (VPCs) per account, leading to connectivity issues and the need for accurate mapping of accounts to resources, which becomes unwieldy as the number of accounts and resources grows.

Innovation Solution

A centralized service that acquires account credentials from cloud providers, generates and manages mappings between cloud accounts and network resources, allowing for the allocation and storage of these mappings to facilitate efficient resource creation and management, including the ability to identify existing mappings and erase them when resources are destroyed.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Quantity of substance

If users create multiple cloud accounts to exceed account limits, then resource quantity increases, but mapping complexity and management burden increase

Engineering Contradiction:
Improvenumber of cloud resourcesVSAvoidmapping management complexity
Core Design Contradiction:
Quantity of substanceVSDevice complexity

Solution Approach 1:

The patent introduces a centralized service as an intermediary between cloud providers and users. This service automatically manages account creation, resource provisioning, and mapping maintenance across multiple cloud accounts. The intermediary handles the complexity of tracking which resources belong to which accounts, eliminating the need for users to manually manage these mappings while enabling resource quantities to exceed single-account limits.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If cloud providers impose account limits on resources, then account security and control are maintained, but resource scalability is restricted

Engineering Contradiction:
Improveaccount control and securityVSAvoidresource scalability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments cloud resources across multiple cloud accounts while maintaining centralized management. Instead of allowing unlimited resources in a single account (which would compromise control and security), the system creates multiple accounts and automatically distributes resources among them. The centralized service maintains the segmentation benefits for security and control while providing unified management that enables scalability across the segmented structure.

Inventive Principle:
Principle #1Segmentation

3Ease of operation

If manual tracking of account-resource mappings is used, then flexibility is maintained, but time consumption and operational efficiency decrease

Engineering Contradiction:
Improveoperational flexibilityVSAvoidtime for mapping management
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The centralized service implements self-service automation where the system automatically performs account creation, resource provisioning, and mapping management without requiring manual user intervention. The service monitors resource allocations, maintains accurate mappings between accounts and resources, and adapts to changes automatically. This eliminates the time-consuming manual tracking while preserving operational flexibility through programmatic control and automated decision-making.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS20220382590A1Cloud provider account mappings
Publication Date: 2022.12.01 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US20220382590A1 patent drawing
  • US20220382590A1 patent drawing
  • US20220382590A1 patent drawing

AI summary

Techniques are described for providing a method of creating and managing mappings between cloud based resources and cloud provider accounts. Specifically, the present disclosure presents a method executed by a centralized service for acquiring account credentials associated with a cloud provider account from a cloud provider. The centralized service is further configured to receive a request to allocate account credentials to a network resources. After receiving the request, the centralized service generates a mapping of the cloud provider account with the network resource based at least in part on the acquired account credentials of the cloud provider account. Finally, the centralized service returns the mapping based on the cloud provider account.