Flexible Rights Management for Cloud Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing cloud-based computing systems lack flexible rights management capabilities, failing to customize access rights for tenants and users, leading to inefficient resource utilization and increased configuration complexity.
Innovation Solution
Implementing a system with 'rights packages,' 'global roles,' and 'tenant roles' to provide flexible access management, allowing service providers to assign and update rights packages and global roles across tenants, while enabling tenants to create custom roles for their users, ensuring secure and tailored access to cloud resources.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If service providers offer standardized rights management across all tenants, then system simplicity is maintained, but tenant-specific customization capability is lost
Solution Approach 1:
The rights management system is segmented into three distinct hierarchical levels: rights packages (tenant-level), global roles (organization-level), and tenant roles (user-level). This segmentation allows standardized packages to be combined with customized roles at different levels, enabling both system simplicity and tenant-specific customization simultaneously.
Solution Approach 2:
The patent implements a nested rights management structure where tenant roles are assigned within the context of global roles, which are in turn assigned within rights packages. This nesting allows customization at the tenant level while maintaining standardized frameworks at higher levels, resolving the contradiction between simplicity and adaptability.
2Adaptability or versatility
If customizable roles are allowed for all users of each tenant, then tenant-specific customization is enabled, but configuration work and system complexity increase
Solution Approach 1:
The system provides pre-defined rights packages that can be automatically assigned to tenants upon provisioning. This preliminary action eliminates the need for tenants to configure rights from scratch, reducing configuration work while still allowing customization through role assignment at the tenant level.
Solution Approach 2:
Global roles serve multiple functions: they define organization-wide rights templates, can be assigned to multiple tenants, and provide a foundation for tenant-specific customization. This multi-functionality reduces overall system complexity by reusing standardized role definitions across different tenant contexts.
3Adaptability or versatility
If multiple levels of rights management are implemented to provide varying rights among tenants and users, then access control flexibility is improved, but system complexity increases
Solution Approach 1:
The rights management system is designed to be dynamic, allowing rights to be inherited and filtered across multiple levels. Tenant roles can dynamically inherit from global roles, and global roles can be filtered based on tenant-specific rights packages, providing flexible access control without requiring complex manual configuration at each level.
Solution Approach 2:
Global roles act as an intermediary layer between standardized rights packages and tenant-specific user roles. This intermediary simplifies the system by providing a standardized template that can be consistently applied across tenants while still allowing for customization at the tenant and user levels.
4Extent of automation
If automated rights management is implemented, then configuration work is reduced, but customization capability for specific tenant needs is limited
Solution Approach 1:
The automated rights management is segmented into automatic package assignment (tenant-level) and manual role assignment (user-level). This segmentation allows high automation for the common case of package assignment while preserving customization capability when tenants need to assign specific global or tenant roles to individual users.
Data Source
AI summary
An example method for assigning rights to utilize cloud resources associated with a service provider's computing hardware is provided. The example method can include defining a rights package including multiple rights pertaining to utilization of the cloud resources. The rights package can be assigned across multiple tenants of the service provider. The example method can also include defining a global role that includes potential rights, where the global role is assignable to individual tenant users of the tenant. The global roles can be made available to multiple tenants using the service provider. The method can further include provisioning filtered rights to utilize the cloud resources to a tenant user of the tenant, the tenant user being assigned the global role. The filtered rights can include rights present in both the potential rights defined for the global role and the rights defined for the rights package.


