Hierarchical Data Access Authorization in Cloud Computing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current data authorization methods in cloud computing environments lack efficient mechanisms for managing multi-tenancy and cross-project space hierarchical architectures, leading to complex data authorization relations and inadequate control over data access across different organizations, especially in public cloud scenarios.

Innovation Solution

A data access method in a cloud computing environment that allows users to manage authorization relations hierarchically across different tenants and project spaces, enabling data providers and users to control access levels and support multi-party authorization transactions by determining the service object space and user identification to provide corresponding access services.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If data transactions are authorized by multiple parties, then data exchange capability is improved, but authorization relation complexity increases and becomes uncontrollable

Engineering Contradiction:
Improvedata exchange capabilityVSAvoidauthorization relation complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the authorization system into hierarchical levels: cloud platform level, tenant level, and project level. Each level handles specific authorization tasks, preventing the need for all parties to authorize all data transactions directly. This segmentation reduces the complexity of multi-party authorization relations while maintaining data exchange capability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces project spaces as intermediary containers that mediate between multiple tenants. The project space acts as a neutral ground where authorized data from different tenants can be accessed without requiring direct pairwise authorization between all tenants. This intermediary structure simplifies the authorization model while enabling versatile data exchange.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If public cloud data authorization is implemented, then data accessibility is improved, but control precision over data access is reduced

Engineering Contradiction:
Improvedata accessibilityVSAvoidcontrol precision over data access
Core Design Contradiction:
Ease of operationVSManufacturing precision

Solution Approach 1:

The patent implements local quality by allowing different authorization policies at different levels of the hierarchy. Each tenant can define specific authorization rules for their data within project spaces, while the cloud platform provides general access controls. This enables precise control over data access at the tenant level while maintaining ease of operation at the platform level.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent introduces dynamic authorization where access rights can be adjusted based on the specific project space and tenant relationships. Authorization is not static but can be modified as tenants join or leave project spaces, or as data sensitivity requirements change. This dynamic approach maintains both accessibility and control precision.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS10922429B2System, method, and apparatus for data access in a cloud computing environment
Publication Date: 2021.02.16 CLOUD INTELLIGENCE ASSETS HOLDING (SINGAPORE) PTE LTD
  • US10922429B2 patent drawing
  • US10922429B2 patent drawing
  • US10922429B2 patent drawing

AI summary

A data access method in a cloud computing environment is disclosed. The method may comprise, in a service object space of the cloud computing environment, receiving a request of a user for accessing a data package, the request including a user identification, determining a service object space of the data package corresponding to the request, and providing the data package to the user according to the service object space of the data package and the user identification.