Cloud Identity Mapping for Local Role-Based Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing cloud-based management tools for hyper-converged infrastructure systems face challenges in securely managing permissions without transferring sensitive customer account information to the cloud, leading to increased cognitive load and security risks due to non-synchronized on-premises and cloud permissions.

Innovation Solution

Implementing a method that maps on-premises customer account identities to cloud identities, storing sensitive information locally, and applying access controls based on local roles, while maintaining the security model by verifying permissions locally without disclosing sensitive information in the cloud.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If on-premises credentials are stored in the cloud to enable command execution, then cloud management functionality is improved, but security risk increases due to storing sensitive customer information in the cloud

Engineering Contradiction:
Improvecloud management functionalityVSAvoidsecurity risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent extracts only the necessary permission verification functionality from the on-premises authentication system while leaving sensitive credentials local. The RBAC service extracts permission decisions without extracting or storing actual credentials, achieving cloud management capability without credential exposure.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an RBAC service as an intermediary between the cloud management portal and on-premises systems. This mediator handles permission verification by mapping cloud identities to local identities and checking permissions without directly storing or transmitting sensitive credentials, thus enabling cloud functionality while maintaining security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If cloud domain permissions are used independently, then cloud management autonomy is improved, but cognitive load increases and permission synchronization issues arise

Engineering Contradiction:
Improvecloud management autonomyVSAvoidpermission management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent makes the on-premises permission system universal by enabling it to serve both local and cloud management operations. The RBAC service allows a single on-premises permission infrastructure to authenticate and authorize both on-premises systems and cloud management portal actions, eliminating the need for separate cloud permission management.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent merges the cloud management permission system with the existing on-premises permission system. By combining these into a unified RBAC framework that uses local identities and permissions for both local and cloud operations, the patent eliminates permission synchronization issues and reduces management complexity while maintaining cloud autonomy.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS12375492B2Role-based access control for cloud features
Publication Date: 2025.07.29 DELL PROD LP
  • US12375492B2 patent drawing
  • US12375492B2 patent drawing

AI summary

An information handling system may include at least one processor and a memory. The information handling system may be configured to: receive, from a cloud management portal, a request to execute a management task, wherein the request includes information regarding a cloud identity associated with the request; determine a local identity that corresponds to the cloud identity; determine whether the local identity has sufficient privileges to execute the management task; and in response to a determination that the local identity does have sufficient privileges to execute the management task, cause the management task to be executed.