Cross-Tenant Resource Sharing via Mapped User Identification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing resource sharing platforms face challenges in enabling cross-tenant access without breaking tenant isolation, requiring users to switch tenants, multiple administrator authorizations, or modifying access credentials, which is inconvenient and inefficient.

Innovation Solution

A method and apparatus that create a target type identification for users to access resources across user groups without breaking isolation, allowing users to access resources through a unique identification that maps to the original user group, enabling seamless cross-tenant collaboration.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If tenant isolation is adopted to ensure data security, then security is improved, but cross-tenant access capability deteriorates

Engineering Contradiction:
Improvedata securityVSAvoidcross-tenant access capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces a mapping relationship as an intermediary mechanism between user groups and resources. When a user from the first user group accesses a resource in the second user group, the system creates a mapping relationship that mediates this cross-tenant access. The mapping relationship acts as a bridge, allowing the first user to access the second user's resource while maintaining the isolation boundaries of both user groups, thus resolving the contradiction between security and cross-tenant access capability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the access control mechanism into distinct components: user group identification, resource identification, and mapping relationships. By segmenting the access control data structure to include separate user group identifiers and resource identifiers along with their mapping relationships, the system enables precise control over cross-tenant access. This segmentation allows the system to maintain tenant isolation while providing targeted cross-access capabilities through the mapping relationships.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If users switch tenants to access resources, then access capability is improved, but operation convenience deteriorates

Engineering Contradiction:
Improveaccess capabilityVSAvoidoperation convenience
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The mapping relationship serves as an intermediary that eliminates the need for users to manually switch tenants. When a user accesses a resource, the system automatically resolves the mapping relationship between the user's user group and the resource's user group, handling the tenant switching logic transparently in the background. This intermediary mechanism provides access capability while maintaining operation convenience by abstracting away the complex tenant switching process.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If multiple administrator authorizations are required for cross-tenant access, then security control is improved, but process efficiency deteriorates

Engineering Contradiction:
Improvesecurity controlVSAvoidprocess efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements preliminary action by pre-establishing mapping relationships between user groups and resources before actual access occurs. The system automatically creates and maintains these mapping relationships, so when a user needs to access a resource, the authorization path is already established. This eliminates the need for multiple real-time administrator authorizations, improving process efficiency while maintaining security control through the pre-configured mapping structure.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The mapping relationship mechanism enables self-service authorization where the system automatically manages cross-tenant access rights without requiring continuous administrator intervention. The mapping relationships are automatically created and updated based on user group and resource identifiers, allowing the system to serve itself in managing access control while maintaining security. This self-service approach dramatically improves process efficiency by eliminating manual authorization steps.

Inventive Principle:
Principle #25Self-service

4Adaptability or versatility

If access credentials are modified for cross-tenant access, then access capability is improved, but system complexity deteriorates

Engineering Contradiction:
Improveaccess capabilityVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent applies universality by using the existing user group identification and resource identification mechanisms to handle cross-tenant access. Instead of creating new access credential systems, the mapping relationship mechanism reuses the existing identifier structures to enable cross-tenant access. This universal approach allows the same identification system to serve both within-tenant and cross-tenant access scenarios, improving access capability without increasing system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20260052150A1Resource sharing method, apparatus, electronic device and storage medium
Publication Date: 2026.02.19 BEIJING ZITIAO NETWORK TECH CO LTD
  • US20260052150A1 patent drawing
  • US20260052150A1 patent drawing
  • US20260052150A1 patent drawing

AI summary

The present disclosure provides a resource sharing method, an apparatus, an electronic device, and a storage medium. The resource sharing method includes: acquiring, in response to a first operation of a first user accessing a target resource and the first user having an access permission to the target resource, an identification of a first user, where the first user belongs to a first user group, and the target resource belongs to a second user group to which a second user belongs; and creating, in response to an identification list associated with the target resource not comprising the identification of the first user, a target type identification for the first user and adding the target type identification to the identification list.