External Access Object for Multi-Tenant Identity Mapping
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In multi-tenant computing systems, there is a lack of efficient mechanisms for a first tenant to control and manage access permissions for users of a second tenant, leading to difficulties in securely sharing resources and data while maintaining data isolation between tenants.
Innovation Solution
The introduction of external access objects that represent users of a second tenant when performing operations in a first tenant, allowing the first tenant to define identity criteria, map users to these objects, and associate them with specific resources and data, thereby controlling access and permissions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If users of a second tenant are allowed to access resources and data of a first tenant, then collaboration and service provision between tenants is enhanced, but data isolation and security between tenants deteriorates
Solution Approach 1:
The patent introduces an external access object as an intermediary mechanism between tenants. This object acts as a mediator that enables users of a second tenant to access resources of a first tenant while maintaining security boundaries. The external access object includes identity criteria, mapping information, and permission associations that control and monitor the access, thus resolving the contradiction between enabling collaboration and maintaining data isolation.
2Reliability
If access permissions are manually managed for each user, then security control is maintained, but system complexity and administrative burden increase
Solution Approach 1:
The external access object serves multiple functions simultaneously: it represents external users, defines identity criteria, establishes mapping relationships, and manages permission associations. This multi-functional design consolidates what would otherwise require separate manual processes into a single unified mechanism, reducing administrative burden while maintaining security control.
Solution Approach 2:
The system creates a virtual representation (copy) of the external user within the first tenant's environment through the external access object. This copy includes all necessary identity and permission information, allowing the system to manage access by operating on the copy rather than directly managing each external user individually, thereby simplifying administration.
3Adaptability or versatility
If users from one tenant can perform operations on another tenant's resources, then service provision is enabled, but permission management and compliance control become difficult
Solution Approach 1:
The external access object is created in advance with pre-defined identity criteria, mapping information, and permission associations before users actually need to access resources. This preliminary setup includes all necessary compliance rules and permission configurations, so that when access is needed, the system can immediately enforce the pre-established policies without requiring real-time permission management decisions.
Data Source
AI summary
Embodiments disclosed herein extend to the use of external access objects in a multi-tenant environment. First and second tenants contract for operations that users of the second tenant will perform in the first tenant. Identity criteria for the users are determined. These users are mapped to an external access object that represents the second tenant users when performing the operations in the first tenant. The external access object is also associated with the resources and/or data that the users of the second tenant will be allowed access to when performing the operations. The users of the second tenant provide a request for access to the resources and/or data to perform operations. Identity criteria are determined and the users are mapped to an external access object based on the identity criteria. It is determined if the user has permission to access the resources and/or data and perform the operations.


