Customer Access Graphs for Self-Service Cloud Resource Permissions
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In the context of software as a service (SaaS), managing access control to customer data stored in cloud-based servers becomes challenging due to the need for host personnel to implement customer-specified access changes, which can lead to errors and delays.
Innovation Solution
A graph structure is used to define access control, where a user associated with the customer is designated as a manager, with nodes representing users and resources and edges specifying access levels, allowing the customer to modify access control through a user interface, while the host maintains ultimate control.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If host personnel manage access control to customer data in cloud-based servers, then access control can be implemented, but implementation becomes more challenging and less efficient with increasing use of SaaS
Solution Approach 1:
The patent implements self-service access control by enabling customers to autonomously manage their own data access permissions through graphical interfaces. Customers can define custom access policies, share data with external users, and control permissions without requiring host personnel intervention. This shifts the operational burden from host staff to customer self-management, directly improving implementation efficiency while reducing operational complexity.
Solution Approach 2:
The patent introduces an intermediary access control system that sits between the customer's data and external users. This intermediary layer provides graphical specification tools that translate customer requirements into enforced access policies. The intermediary automates the access control implementation process, eliminating manual intervention by host personnel while maintaining secure control over customer data in cloud-based SaaS environments.
2Reliability
If host personnel manually modify access control based on customer requests, then access control changes can be implemented, but errors and delays occur
Solution Approach 1:
By enabling customers to directly configure and modify their own access control settings through graphical interfaces, the system eliminates manual intervention by host personnel. Customers can immediately implement access control changes by defining custom policies and sharing data with external users, ensuring accurate implementation of their specific requirements without transcription errors or delays associated with manual processing.
Solution Approach 2:
The patent implements preliminary action by providing customers with pre-configured graphical tools and templates for defining access control policies. These tools guide customers through the policy creation process beforehand, ensuring that access control rules are correctly specified before implementation. The system validates policies in advance and prepares access control configurations ready for immediate deployment, eliminating delays and errors associated with manual review and implementation by host personnel.
Data Source
AI summary
A method of controlling access to resources provided to a customer via a host includes generating a graph structure defining access control to the resources. The graph structure designates a user associated with the customer as a manager. The graph structure includes a user node associated with the user designated as the manager, resource nodes, each resource node associated with a respective resource among the resources, and edges, each edge extending from the user node associated with the user designated as the manager to each of the resource nodes. Each edge specifies an edge value that defines access provided to the user designated as the manager for the respective resource among the resources. The method also includes modifying the graph structure based on input from the user designated as the manager to modify the access control to the resources.


