Customer Access Graphs for Self-Service Cloud Resource Permissions

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In the context of software as a service (SaaS), managing access control to customer data stored in cloud-based servers becomes challenging due to the need for host personnel to implement customer-specified access changes, which can lead to errors and delays.

Innovation Solution

A graph structure is used to define access control, where a user associated with the customer is designated as a manager, with nodes representing users and resources and edges specifying access levels, allowing the customer to modify access control through a user interface, while the host maintains ultimate control.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If host personnel manage access control to customer data in cloud-based servers, then access control can be implemented, but implementation becomes more challenging and less efficient with increasing use of SaaS

Engineering Contradiction:
Improveaccess control implementation efficiencyVSAvoidaccess control management complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent implements self-service access control by enabling customers to autonomously manage their own data access permissions through graphical interfaces. Customers can define custom access policies, share data with external users, and control permissions without requiring host personnel intervention. This shifts the operational burden from host staff to customer self-management, directly improving implementation efficiency while reducing operational complexity.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent introduces an intermediary access control system that sits between the customer's data and external users. This intermediary layer provides graphical specification tools that translate customer requirements into enforced access policies. The intermediary automates the access control implementation process, eliminating manual intervention by host personnel while maintaining secure control over customer data in cloud-based SaaS environments.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If host personnel manually modify access control based on customer requests, then access control changes can be implemented, but errors and delays occur

Engineering Contradiction:
Improveaccess control accuracyVSAvoidaccess control implementation time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

By enabling customers to directly configure and modify their own access control settings through graphical interfaces, the system eliminates manual intervention by host personnel. Customers can immediately implement access control changes by defining custom policies and sharing data with external users, ensuring accurate implementation of their specific requirements without transcription errors or delays associated with manual processing.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent implements preliminary action by providing customers with pre-configured graphical tools and templates for defining access control policies. These tools guide customers through the policy creation process beforehand, ensuring that access control rules are correctly specified before implementation. The system validates policies in advance and prepares access control configurations ready for immediate deployment, eliminating delays and errors associated with manual review and implementation by host personnel.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20250220017A1Customer access management system and method
Publication Date: 2025.07.03 CHARLES RIVER LABORATORIES INTERNATIONAL INC
  • US20250220017A1 patent drawing
  • US20250220017A1 patent drawing
  • US20250220017A1 patent drawing

AI summary

A method of controlling access to resources provided to a customer via a host includes generating a graph structure defining access control to the resources. The graph structure designates a user associated with the customer as a manager. The graph structure includes a user node associated with the user designated as the manager, resource nodes, each resource node associated with a respective resource among the resources, and edges, each edge extending from the user node associated with the user designated as the manager to each of the resource nodes. Each edge specifies an edge value that defines access provided to the user designated as the manager for the respective resource among the resources. The method also includes modifying the graph structure based on input from the user designated as the manager to modify the access control to the resources.