Cloud Identity Mapping for Local Role-Based Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing cloud-based management tools for hyper-converged infrastructure systems face challenges in securely managing permissions without transferring sensitive customer account information to the cloud, leading to increased cognitive load and security risks due to non-synchronized on-premises and cloud permissions.
Innovation Solution
Implementing a method that maps on-premises customer account identities to cloud identities, storing sensitive information locally, and applying access controls based on local roles, while maintaining the security model by verifying permissions locally without disclosing sensitive information in the cloud.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If on-premises credentials are stored in the cloud to enable command execution, then cloud management functionality is improved, but security risk increases due to storing sensitive customer information in the cloud
Solution Approach 1:
The patent extracts only the necessary permission verification functionality from the on-premises authentication system while leaving sensitive credentials local. The RBAC service extracts permission decisions without extracting or storing actual credentials, achieving cloud management capability without credential exposure.
Solution Approach 2:
The patent introduces an RBAC service as an intermediary between the cloud management portal and on-premises systems. This mediator handles permission verification by mapping cloud identities to local identities and checking permissions without directly storing or transmitting sensitive credentials, thus enabling cloud functionality while maintaining security.
2Adaptability or versatility
If cloud domain permissions are used independently, then cloud management autonomy is improved, but cognitive load increases and permission synchronization issues arise
Solution Approach 1:
The patent makes the on-premises permission system universal by enabling it to serve both local and cloud management operations. The RBAC service allows a single on-premises permission infrastructure to authenticate and authorize both on-premises systems and cloud management portal actions, eliminating the need for separate cloud permission management.
Solution Approach 2:
The patent merges the cloud management permission system with the existing on-premises permission system. By combining these into a unified RBAC framework that uses local identities and permissions for both local and cloud operations, the patent eliminates permission synchronization issues and reduces management complexity while maintaining cloud autonomy.
Data Source
AI summary
An information handling system may include at least one processor and a memory. The information handling system may be configured to: receive, from a cloud management portal, a request to execute a management task, wherein the request includes information regarding a cloud identity associated with the request; determine a local identity that corresponds to the cloud identity; determine whether the local identity has sufficient privileges to execute the management task; and in response to a determination that the local identity does have sufficient privileges to execute the management task, cause the management task to be executed.

