External Access Object for Multi-Tenant Identity Mapping

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In multi-tenant computing systems, there is a lack of efficient mechanisms for a first tenant to control and manage access permissions for users of a second tenant, leading to difficulties in securely sharing resources and data while maintaining data isolation between tenants.

Innovation Solution

The introduction of external access objects that represent users of a second tenant when performing operations in a first tenant, allowing the first tenant to define identity criteria, map users to these objects, and associate them with specific resources and data, thereby controlling access and permissions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If users of a second tenant are allowed to access resources and data of a first tenant, then collaboration and service provision between tenants is enhanced, but data isolation and security between tenants deteriorates

Engineering Contradiction:
Improvecollaboration capabilityVSAvoiddata isolation
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces an external access object as an intermediary mechanism between tenants. This object acts as a mediator that enables users of a second tenant to access resources of a first tenant while maintaining security boundaries. The external access object includes identity criteria, mapping information, and permission associations that control and monitor the access, thus resolving the contradiction between enabling collaboration and maintaining data isolation.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If access permissions are manually managed for each user, then security control is maintained, but system complexity and administrative burden increase

Engineering Contradiction:
Improvesecurity controlVSAvoidaccess management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The external access object serves multiple functions simultaneously: it represents external users, defines identity criteria, establishes mapping relationships, and manages permission associations. This multi-functional design consolidates what would otherwise require separate manual processes into a single unified mechanism, reducing administrative burden while maintaining security control.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system creates a virtual representation (copy) of the external user within the first tenant's environment through the external access object. This copy includes all necessary identity and permission information, allowing the system to manage access by operating on the copy rather than directly managing each external user individually, thereby simplifying administration.

Inventive Principle:
Principle #26Copying

3Adaptability or versatility

If users from one tenant can perform operations on another tenant's resources, then service provision is enabled, but permission management and compliance control become difficult

Engineering Contradiction:
Improveservice provision capabilityVSAvoidpermission management
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The external access object is created in advance with pre-defined identity criteria, mapping information, and permission associations before users actually need to access resources. This preliminary setup includes all necessary compliance rules and permission configurations, so that when access is needed, the system can immediately enforce the pre-established policies without requiring real-time permission management decisions.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8843648B2External access and partner delegation
Publication Date: 2014.09.23 MICROSOFT TECHNOLOGY LICENSING LLC
  • US8843648B2 patent drawing
  • US8843648B2 patent drawing
  • US8843648B2 patent drawing

AI summary

Embodiments disclosed herein extend to the use of external access objects in a multi-tenant environment. First and second tenants contract for operations that users of the second tenant will perform in the first tenant. Identity criteria for the users are determined. These users are mapped to an external access object that represents the second tenant users when performing the operations in the first tenant. The external access object is also associated with the resources and/or data that the users of the second tenant will be allowed access to when performing the operations. The users of the second tenant provide a request for access to the resources and/or data to perform operations. Identity criteria are determined and the users are mapped to an external access object based on the identity criteria. It is determined if the user has permission to access the resources and/or data and perform the operations.