Cloud Service Role Segmentation for Privilege Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional cloud service systems lack the ability to configure roles related to contract management, leading to potential over-privileging of general users who may inadvertently access or use privileges from other departments.
Innovation Solution
A service system that allows for the configuration of roles by designating a contract administrator with specific privileges, limiting their access to only those necessary for their management tasks, thereby preventing unintentional operations and reducing the burden on tenant administrators.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If general users are given broad access privileges in cloud services, then ease of operation is improved, but security and reliability deteriorate due to potential unauthorized access to other departments' privileges
Solution Approach 1:
The patent segments user privileges into two distinct categories: contract administrator privileges and general user privileges. Contract administrators are granted specific privileges related to contract management (viewing contract information, managing service usage), while general users receive only the minimum necessary privileges for their operational tasks. This segmentation prevents general users from accessing contract-related functions and other departments' privileges, thereby resolving the contradiction between ease of operation and privilege security.
2Device complexity
If contract administrator privileges are not specifically configured, then device complexity is reduced, but harmful factors increase due to potential erroneous operations by over-privileged users
Solution Approach 1:
The patent applies local quality by assigning different privilege characteristics to different user roles. Contract administrators are given a specific set of privileges localized to contract management functions, while general users have privileges localized to their operational tasks. This localized privilege assignment ensures that each user group has exactly the privileges needed for their specific functions, preventing erroneous operations while maintaining system configuration simplicity through automated role-based assignment.
3Reliability
If tenant administrators manually manage all user privileges, then reliability is improved through centralized control, but productivity deteriorates due to increased administrative burden
Solution Approach 1:
The patent implements self-service by enabling contract administrators to autonomously manage their own privileges and the privileges of users within their contracted services. The system automatically assigns appropriate privileges based on the contract configuration, eliminating the need for tenant administrators to manually manage each user's privileges. This self-service mechanism maintains reliability through automated consistent privilege assignment while significantly improving productivity by reducing the administrative burden on tenant administrators.
Data Source
AI summary
A service system includes a server that provides a service as a cloud service, and a device that receives the service, wherein a terminal device that is operated by a contract administrator sends identification information of the contract administrator and information related to a contract of the service, to the server, and wherein the server includes a user information storage unit that specifies a role associated with the identification information of the contract administrator, a communication unit that receives the identification information of the contract administrator and the information related to the contract, and an information registration unit that registers the identification information of the contract administrator, contract identification information generated based on the contract, and an operation privilege related to the contract based on the role specified in the user information storage unit, in association with each other, in a contract operation privilege information storage.


