Delegated Administration for Hosted Web Resources
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Administering Web sites hosted by Internet Service Providers (ISPs) is time-consuming and costly, especially for personal sites, due to the labor-intensive and expensive nature of computer security measures, which often leads to ISPs supporting only large company Web sites.
Innovation Solution
The Internet Information Services (IIS) Delegation Administration (DA) framework allows authorized users, including personal Web site owners, to perform administration tasks on hosted resources without requiring administrator intervention, by implementing role-based access permissions and delegating authority independently of their group membership.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional administrator intervention is used for security management, then security reliability is improved, but administrative time and cost increase
Solution Approach 1:
The patent implements self-service security management by enabling authorized users to perform administrative tasks independently through delegated authority. Users can manage their own resources, configure security settings, and perform operations without requiring administrator intervention, thus reducing administrative time while maintaining security through role-based access control and audit trails
Solution Approach 2:
The system introduces an intermediary delegation framework that acts as a mediator between administrators and users. This framework delegates specific authorities to users through a structured authorization system, allowing users to perform administrative tasks within defined boundaries while maintaining security oversight through audit logs and role-based access control
2Reliability
If traditional administrator intervention is used for security management, then security reliability is improved, but cost increases
Solution Approach 1:
The system enables users to independently perform administrative tasks through delegated authority, eliminating the need for expensive administrator intervention for routine operations. Users can manage their own resources, configure settings, and perform security-related tasks within their authorized scope, significantly reducing administrative costs while maintaining security through role-based access control
Solution Approach 2:
The delegation framework serves as an intermediary that automates security management between administrators and users. By implementing automated authorization checks, role-based access control, and audit trails, the system reduces the need for expensive human administrator intervention while maintaining security reliability
3Ease of operation
If delegated authority is implemented independently of administrator group membership, then ease of operation is improved, but device complexity increases
Solution Approach 1:
The system segments administrative authority into discrete, delegable units that can be independently assigned to users. By breaking down administrator privileges into specific operational authorities, the system enables fine-grained delegation without requiring users to be members of administrator groups, improving ease of operation while managing complexity through modular authorization
Solution Approach 2:
The system changes the parameter of authorization from group-based membership to individual delegated authority. By transforming the authorization model from static group membership to dynamic delegated permissions, the system improves ease of operation while managing system complexity through structured role-based access control and audit mechanisms
Data Source
AI summary
Systems and methods for delegating access to resources hosted in a distributed computing environment are described. In one aspect, a server hosts a set of resources. The server receives a request from a user to perform an operation with respect to one of the hosted resources. Responsive to receiving the request, the server determines whether the user has already been delegated authority to perform the operation. The delegated authority is independent of whether the user is a member of an administrators group associated with any resource of the server.


