Delegated Administration for Hosted Web Resources

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Administering Web sites hosted by Internet Service Providers (ISPs) is time-consuming and costly, especially for personal sites, due to the labor-intensive and expensive nature of computer security measures, which often leads to ISPs supporting only large company Web sites.

Innovation Solution

The Internet Information Services (IIS) Delegation Administration (DA) framework allows authorized users, including personal Web site owners, to perform administration tasks on hosted resources without requiring administrator intervention, by implementing role-based access permissions and delegating authority independently of their group membership.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional administrator intervention is used for security management, then security reliability is improved, but administrative time and cost increase

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidadministrative time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements self-service security management by enabling authorized users to perform administrative tasks independently through delegated authority. Users can manage their own resources, configure security settings, and perform operations without requiring administrator intervention, thus reducing administrative time while maintaining security through role-based access control and audit trails

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system introduces an intermediary delegation framework that acts as a mediator between administrators and users. This framework delegates specific authorities to users through a structured authorization system, allowing users to perform administrative tasks within defined boundaries while maintaining security oversight through audit logs and role-based access control

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If traditional administrator intervention is used for security management, then security reliability is improved, but cost increases

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidadministrative cost
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The system enables users to independently perform administrative tasks through delegated authority, eliminating the need for expensive administrator intervention for routine operations. Users can manage their own resources, configure settings, and perform security-related tasks within their authorized scope, significantly reducing administrative costs while maintaining security through role-based access control

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The delegation framework serves as an intermediary that automates security management between administrators and users. By implementing automated authorization checks, role-based access control, and audit trails, the system reduces the need for expensive human administrator intervention while maintaining security reliability

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If delegated authority is implemented independently of administrator group membership, then ease of operation is improved, but device complexity increases

Engineering Contradiction:
Improveease of operationVSAvoidsystem complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The system segments administrative authority into discrete, delegable units that can be independently assigned to users. By breaking down administrator privileges into specific operational authorities, the system enables fine-grained delegation without requiring users to be members of administrator groups, improving ease of operation while managing complexity through modular authorization

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system changes the parameter of authorization from group-based membership to individual delegated authority. By transforming the authorization model from static group membership to dynamic delegated permissions, the system improves ease of operation while managing system complexity through structured role-based access control and audit mechanisms

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS7827595B2Delegated administration of a hosted resource
Publication Date: 2010.11.02 MICROSOFT TECHNOLOGY LICENSING LLC
  • US7827595B2 patent drawing
  • US7827595B2 patent drawing
  • US7827595B2 patent drawing

AI summary

Systems and methods for delegating access to resources hosted in a distributed computing environment are described. In one aspect, a server hosts a set of resources. The server receives a request from a user to perform an operation with respect to one of the hosted resources. Responsive to receiving the request, the server determines whether the user has already been delegated authority to perform the operation. The delegated authority is independent of whether the user is a member of an administrators group associated with any resource of the server.