Flexible Rights Management for Cloud Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cloud-based computing systems lack flexible rights management capabilities, failing to customize access rights for tenants and users, leading to inefficient resource utilization and increased configuration complexity.

Innovation Solution

Implementing a system with 'rights packages,' 'global roles,' and 'tenant roles' to provide flexible access management, allowing service providers to assign and update rights packages and global roles across tenants, while enabling tenants to create custom roles for their users, ensuring secure and tailored access to cloud resources.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If service providers offer standardized rights management across all tenants, then system simplicity is maintained, but tenant-specific customization capability is lost

Engineering Contradiction:
Improverights management system complexityVSAvoidtenant-specific rights customization
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The rights management system is segmented into three distinct hierarchical levels: rights packages (tenant-level), global roles (organization-level), and tenant roles (user-level). This segmentation allows standardized packages to be combined with customized roles at different levels, enabling both system simplicity and tenant-specific customization simultaneously.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements a nested rights management structure where tenant roles are assigned within the context of global roles, which are in turn assigned within rights packages. This nesting allows customization at the tenant level while maintaining standardized frameworks at higher levels, resolving the contradiction between simplicity and adaptability.

Inventive Principle:
Principle #7Nested doll (Nesting)

2Adaptability or versatility

If customizable roles are allowed for all users of each tenant, then tenant-specific customization is enabled, but configuration work and system complexity increase

Engineering Contradiction:
Improvetenant-specific rights customizationVSAvoidrights management system complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system provides pre-defined rights packages that can be automatically assigned to tenants upon provisioning. This preliminary action eliminates the need for tenants to configure rights from scratch, reducing configuration work while still allowing customization through role assignment at the tenant level.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

Global roles serve multiple functions: they define organization-wide rights templates, can be assigned to multiple tenants, and provide a foundation for tenant-specific customization. This multi-functionality reduces overall system complexity by reusing standardized role definitions across different tenant contexts.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Adaptability or versatility

If multiple levels of rights management are implemented to provide varying rights among tenants and users, then access control flexibility is improved, but system complexity increases

Engineering Contradiction:
Improveaccess control flexibilityVSAvoidrights management system complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The rights management system is designed to be dynamic, allowing rights to be inherited and filtered across multiple levels. Tenant roles can dynamically inherit from global roles, and global roles can be filtered based on tenant-specific rights packages, providing flexible access control without requiring complex manual configuration at each level.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

Global roles act as an intermediary layer between standardized rights packages and tenant-specific user roles. This intermediary simplifies the system by providing a standardized template that can be consistently applied across tenants while still allowing for customization at the tenant and user levels.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Extent of automation

If automated rights management is implemented, then configuration work is reduced, but customization capability for specific tenant needs is limited

Engineering Contradiction:
Improverights management automationVSAvoidtenant-specific rights customization
Core Design Contradiction:
Extent of automationVSAdaptability or versatility

Solution Approach 1:

The automated rights management is segmented into automatic package assignment (tenant-level) and manual role assignment (user-level). This segmentation allows high automation for the common case of package assignment while preserving customization capability when tenants need to assign specific global or tenant roles to individual users.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11122053B2Flexible rights management for cloud-based access to computing resources
Publication Date: 2021.09.14 VMWARE INC
  • US11122053B2 patent drawing
  • US11122053B2 patent drawing
  • US11122053B2 patent drawing

AI summary

An example method for assigning rights to utilize cloud resources associated with a service provider's computing hardware is provided. The example method can include defining a rights package including multiple rights pertaining to utilization of the cloud resources. The rights package can be assigned across multiple tenants of the service provider. The example method can also include defining a global role that includes potential rights, where the global role is assignable to individual tenant users of the tenant. The global roles can be made available to multiple tenants using the service provider. The method can further include provisioning filtered rights to utilize the cloud resources to a tenant user of the tenant, the tenant user being assigned the global role. The filtered rights can include rights present in both the potential rights defined for the global role and the rights defined for the rights package.