Hierarchical Service Control Policies for Cloud Feature Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing cloud computing environments lack effective methods for defining and enforcing service control policies that allow hierarchical control of service availability and access, leading to potential security and management challenges.
Innovation Solution
A service control repository and policy framework that defines service control policies through a hierarchy of entities, enabling controlled availability and access to services and features based on entity levels.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If a hierarchy of entities is implemented to control service availability, then access control precision is improved, but system complexity increases
Solution Approach 1:
The system segments service control into multiple hierarchical levels (global, tenant, service, feature) where each level can independently define policies. This segmentation allows precise control at each layer while maintaining manageable complexity through modular policy definitions rather than a monolithic control structure.
Solution Approach 2:
The patent introduces a hierarchical dimension to service control, organizing policies across multiple levels (global → tenant → service → feature). This dimensional organization enables precise access control by evaluating policies at each level sequentially, transforming a complex single-layer control problem into a structured multi-layer evaluation process.
2Adaptability or versatility
If multiple entities are allowed to control service features, then management flexibility is improved, but policy enforcement difficulty increases
Solution Approach 1:
The system performs preliminary evaluation of service control policies at each hierarchical level before service execution. By pre-evaluating policies at global, tenant, service, and feature levels in sequence, the system determines service availability upfront, avoiding complex runtime enforcement decisions and simplifying the enforcement process.
Solution Approach 2:
The patent introduces an intermediary service control policy evaluation mechanism that mediates between multiple entities (global provider, tenant, service provider) and the service execution. This intermediary evaluates policies at each hierarchical level and determines final service availability, simplifying the enforcement process by centralizing the decision logic rather than requiring direct coordination between all entities.
Data Source
AI summary
Embodiments described herein are generally related to systems and methods for providing cloud environments, for use by tenants of a cloud infrastructure environment in accessing software products, services, or other offerings associated with the environment, including methods for defining and enforcing service control policies directed to services and service features. In accordance with an embodiment, the system comprises a service control repository or service catalog that provides a definition of the services and service features, together with service control policies or rules that define availability or access to the service features. A service control policy framework, comprising a feature management service, determines, by reference to a hierarchy of entities defining the service control policies, which different entities can control the availability of particular services or service features to end users.


