Custom Role Creation for Granular Network Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current computer network access control systems lack the ability to customize user roles and privileges effectively, limiting service providers' control over user access and service offerings in multi-tenant environments.
Innovation Solution
The system allows service providers to create custom roles with specific sets of actions and privileges, enabling granular control over user access by associating users with these custom roles, which can be modified based on user input, thereby extending the control provided by pre-defined roles.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If pre-defined roles from open-source software are used, then system reliability is maintained, but adaptability to customize user access control is insufficient
Solution Approach 1:
The system segments role management into two distinct components: pre-defined roles from open-source software that ensure system reliability, and custom roles that can be created and configured by service providers to meet specific customization needs. This segmentation allows both reliability and adaptability to coexist by isolating the stability-providing elements from the flexibility-providing elements.
Solution Approach 2:
The system merges pre-defined roles and custom roles into a unified role management framework where both types of roles can be assigned to users simultaneously. This combination allows the system to leverage the stability of pre-defined roles while incorporating the flexibility of custom roles, resolving the contradiction between reliability and adaptability.
2Adaptability or versatility
If custom roles are created with specific capabilities, then adaptability of access control is improved, but device complexity increases
Solution Approach 1:
The system performs preliminary action by providing pre-defined roles with common capability sets before custom role creation is needed. Service providers can start with these pre-configured roles and only create custom roles when specific customization requirements arise, reducing the overall complexity while maintaining necessary adaptability.
Solution Approach 2:
The role management system is designed to be dynamic, allowing service providers to create, modify, or delete custom roles based on changing requirements. This dynamic approach means that complexity only increases when and where it is needed, rather than being statically present throughout the entire system.
3Adaptability or versatility
If granular control over user actions is implemented, then adaptability of service offerings is improved, but ease of operation decreases
Solution Approach 1:
The system implements a universal capability framework where capabilities are standardized and can be applied across multiple roles and users. This multi-functionality allows granular control to be achieved through a consistent interface, reducing operational complexity while maintaining fine-grained control over user actions and service access.
Data Source
AI summary
This disclosure is directed to devices, systems, and techniques for enforcing access to resources within a computer network. In some examples, a system includes a network managed by a service provider and configured to provide a plurality of microservices to a plurality of tenants each having one or more users and a controller having access to the network. The controller is configured to output, to a user interface, data indicative of a plurality of capabilities for presentation by the user interface and receive, from the user interface, data indicative of a user selection of a set of capabilities and a user selection of a new role identifier. The controller is further configured to create, based on the set of capabilities and the role identifier, a role which enables access to a set of actions within a computer network, the set of actions corresponding to the set of capabilities.


