Cloud Credential Repository for Enterprise Billing Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cloud computing presents challenges for enterprise management, including lack of control over resource usage, difficulties in data sharing, and security concerns due to individual developers' control over cloud accounts, leading to potential misuse and data loss.

Innovation Solution

A cloud management system with a credential repository that manages user accounts through a multi-tiered, multi-protocol system, allowing administrative control over billing, policy enforcement, and data sharing, while separating master and API credentials to maintain control and security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If individual developers requisition cloud resources separately through personal cloud accounts, then developers can quickly access and use cloud resources on demand, but enterprise managers lose control over resource usage and budget allocation

Engineering Contradiction:
ImproveDeveloper access to cloud resourcesVSAvoidEnterprise resource management complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The system segments cloud resource management into two distinct layers: enterprise-level management (billing, policy, budget control) and individual developer access (resource provisioning, usage). This segmentation allows developers to access resources independently while enterprise managers maintain oversight through separate management interfaces.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary enterprise cloud management system that sits between cloud providers and individual developers. This intermediary handles billing consolidation, policy enforcement, and resource allocation, enabling both rapid developer access and centralized enterprise control without direct conflict.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If cloud accounts are under individual user control, then users can independently manage their resources, but IT departments cannot enforce corporate security policies or audit data storage

Engineering Contradiction:
ImproveUser independence in resource managementVSAvoidCorporate policy enforcement
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system implements preliminary action by pre-configuring security policies, encryption requirements, and compliance rules at the enterprise level before developers access cloud resources. These policies are automatically enforced through the management system, ensuring corporate requirements are met before individual usage begins.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements feedback mechanisms where the enterprise management system continuously monitors and audits individual developer cloud usage. Usage data, billing information, and resource access patterns are fed back to enterprise managers, enabling real-time policy enforcement and security compliance verification.

Inventive Principle:
Principle #23Feedback

3Productivity

If developers store company data in personal cloud accounts, then data accessibility is improved, but data security and recovery become problematic when employees leave

Engineering Contradiction:
ImproveData accessibilityVSAvoidData security and recovery
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system merges individual developer cloud accounts with enterprise-controlled accounts. Data stored in the cloud is associated with both the individual developer's access rights and enterprise ownership rights. This merging ensures that data remains accessible to the individual during employment while maintaining enterprise control for security and recovery purposes.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The enterprise management system acts as an intermediary that mediates between individual data access needs and corporate data protection requirements. It enables developers to access and store data efficiently while simultaneously enforcing encryption, access controls, and recovery protocols to protect corporate assets.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Ease of operation

If data sharing requires individual account ID management, then precise access control is achieved, but data sharing becomes cumbersome and time-consuming

Engineering Contradiction:
ImproveData sharing simplicityVSAvoidTime to manage data sharing
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The patent implements a universal enterprise-level data sharing mechanism that works across all individual developer accounts. Instead of managing sharing at the individual account ID level, the system provides a unified interface where enterprise managers can share data with multiple developers or groups simultaneously, reducing repetitive manual configuration.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system creates abstracted copies or representations of data access permissions at the enterprise level, which can be rapidly replicated and distributed to multiple individual accounts. This copying mechanism eliminates the need to manually configure each individual account's sharing settings, significantly reducing time and effort.

Inventive Principle:
Principle #26Copying

Data Source

PatentEP2383956B1Cloud-based billing, credential, and data sharing management system
Publication Date: 2017.09.06 ACCENTURE GLOBAL SERVICES LTD
  • EP2383956B1 patent drawingFigure 1
  • EP2383956B1 patent drawingFigure 2
  • EP2383956B1 patent drawingFigure 3

AI summary

A novel solution is provided that utilizes the two-credential characteristics of accessing cloud-hosted data in a portal-oriented enterprise-specific solution. Cloud computing resources may be accessed through a separate, enterprise-specific portal clients used to manage a set of cloud service accounts. Individuals (e.g., employees of the enterprise or company) may access cloud computing resources via an instance of the portal client, and any communication between individuals in an enterprise and cloud services may be facilitated through the portal. Each portal client may also be configured to be compatible with any cloud service vendor.