Cloud Credential Repository for Enterprise Billing Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Cloud computing presents challenges for enterprise management, including lack of control over resource usage, difficulties in data sharing, and security concerns due to individual developers' control over cloud accounts, leading to potential misuse and data loss.
Innovation Solution
A cloud management system with a credential repository that manages user accounts through a multi-tiered, multi-protocol system, allowing administrative control over billing, policy enforcement, and data sharing, while separating master and API credentials to maintain control and security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If individual developers requisition cloud resources separately through personal cloud accounts, then developers can quickly access and use cloud resources on demand, but enterprise managers lose control over resource usage and budget allocation
Solution Approach 1:
The system segments cloud resource management into two distinct layers: enterprise-level management (billing, policy, budget control) and individual developer access (resource provisioning, usage). This segmentation allows developers to access resources independently while enterprise managers maintain oversight through separate management interfaces.
Solution Approach 2:
The patent introduces an intermediary enterprise cloud management system that sits between cloud providers and individual developers. This intermediary handles billing consolidation, policy enforcement, and resource allocation, enabling both rapid developer access and centralized enterprise control without direct conflict.
2Adaptability or versatility
If cloud accounts are under individual user control, then users can independently manage their resources, but IT departments cannot enforce corporate security policies or audit data storage
Solution Approach 1:
The system implements preliminary action by pre-configuring security policies, encryption requirements, and compliance rules at the enterprise level before developers access cloud resources. These policies are automatically enforced through the management system, ensuring corporate requirements are met before individual usage begins.
Solution Approach 2:
The patent implements feedback mechanisms where the enterprise management system continuously monitors and audits individual developer cloud usage. Usage data, billing information, and resource access patterns are fed back to enterprise managers, enabling real-time policy enforcement and security compliance verification.
3Productivity
If developers store company data in personal cloud accounts, then data accessibility is improved, but data security and recovery become problematic when employees leave
Solution Approach 1:
The system merges individual developer cloud accounts with enterprise-controlled accounts. Data stored in the cloud is associated with both the individual developer's access rights and enterprise ownership rights. This merging ensures that data remains accessible to the individual during employment while maintaining enterprise control for security and recovery purposes.
Solution Approach 2:
The enterprise management system acts as an intermediary that mediates between individual data access needs and corporate data protection requirements. It enables developers to access and store data efficiently while simultaneously enforcing encryption, access controls, and recovery protocols to protect corporate assets.
4Ease of operation
If data sharing requires individual account ID management, then precise access control is achieved, but data sharing becomes cumbersome and time-consuming
Solution Approach 1:
The patent implements a universal enterprise-level data sharing mechanism that works across all individual developer accounts. Instead of managing sharing at the individual account ID level, the system provides a unified interface where enterprise managers can share data with multiple developers or groups simultaneously, reducing repetitive manual configuration.
Solution Approach 2:
The system creates abstracted copies or representations of data access permissions at the enterprise level, which can be rapidly replicated and distributed to multiple individual accounts. This copying mechanism eliminates the need to manually configure each individual account's sharing settings, significantly reducing time and effort.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A novel solution is provided that utilizes the two-credential characteristics of accessing cloud-hosted data in a portal-oriented enterprise-specific solution. Cloud computing resources may be accessed through a separate, enterprise-specific portal clients used to manage a set of cloud service accounts. Individuals (e.g., employees of the enterprise or company) may access cloud computing resources via an instance of the portal client, and any communication between individuals in an enterprise and cloud services may be facilitated through the portal. Each portal client may also be configured to be compatible with any cloud service vendor.