Cloud Service Role Segmentation for Privilege Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional cloud service systems lack the ability to configure roles related to contract management, leading to potential over-privileging of general users who may inadvertently access or use privileges from other departments.

Innovation Solution

A service system that allows for the configuration of roles by designating a contract administrator with specific privileges, limiting their access to only those necessary for their management tasks, thereby preventing unintentional operations and reducing the burden on tenant administrators.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If general users are given broad access privileges in cloud services, then ease of operation is improved, but security and reliability deteriorate due to potential unauthorized access to other departments' privileges

Engineering Contradiction:
Improveuser access convenienceVSAvoidprivilege security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments user privileges into two distinct categories: contract administrator privileges and general user privileges. Contract administrators are granted specific privileges related to contract management (viewing contract information, managing service usage), while general users receive only the minimum necessary privileges for their operational tasks. This segmentation prevents general users from accessing contract-related functions and other departments' privileges, thereby resolving the contradiction between ease of operation and privilege security.

Inventive Principle:
Principle #1Segmentation

2Device complexity

If contract administrator privileges are not specifically configured, then device complexity is reduced, but harmful factors increase due to potential erroneous operations by over-privileged users

Engineering Contradiction:
Improvesystem configuration simplicityVSAvoiderroneous operations risk
Core Design Contradiction:
Device complexityVSObject-generated harmful factors

Solution Approach 1:

The patent applies local quality by assigning different privilege characteristics to different user roles. Contract administrators are given a specific set of privileges localized to contract management functions, while general users have privileges localized to their operational tasks. This localized privilege assignment ensures that each user group has exactly the privileges needed for their specific functions, preventing erroneous operations while maintaining system configuration simplicity through automated role-based assignment.

Inventive Principle:
Principle #3Local quality

3Reliability

If tenant administrators manually manage all user privileges, then reliability is improved through centralized control, but productivity deteriorates due to increased administrative burden

Engineering Contradiction:
Improveprivilege management controlVSAvoidadministration efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements self-service by enabling contract administrators to autonomously manage their own privileges and the privileges of users within their contracted services. The system automatically assigns appropriate privileges based on the contract configuration, eliminating the need for tenant administrators to manually manage each user's privileges. This self-service mechanism maintains reliability through automated consistent privilege assignment while significantly improving productivity by reducing the administrative burden on tenant administrators.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11451557B2Service system and information registration method
Publication Date: 2022.09.20 RICOH CO LTD
  • US11451557B2 patent drawing
  • US11451557B2 patent drawing
  • US11451557B2 patent drawing

AI summary

A service system includes a server that provides a service as a cloud service, and a device that receives the service, wherein a terminal device that is operated by a contract administrator sends identification information of the contract administrator and information related to a contract of the service, to the server, and wherein the server includes a user information storage unit that specifies a role associated with the identification information of the contract administrator, a communication unit that receives the identification information of the contract administrator and the information related to the contract, and an information registration unit that registers the identification information of the contract administrator, contract identification information generated based on the contract, and an operation privilege related to the contract based on the role specified in the user information storage unit, in association with each other, in a contract operation privilege information storage.