Mirror Account Segmentation for Multi-Tenant Cloud Identity
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In multi-tenant environments, managing user identities for data processing in hybrid on-premises and cloud architectures is challenging, particularly when unattended tasks on cloud clusters require access to multiple services, as single service accounts complicate auditing and authorization, and expose user data to security risks.
Innovation Solution
The creation and use of mirror accounts, which are unique to each user and mirror their enterprise accounts, allowing for transparent authorization, authentication, and auditing of data processing jobs on cloud clusters without exposing access to other cloud services, thereby limiting potential security breaches.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a single service account is used for all users to access cloud clusters, then ease of operation is improved, but auditing precision and security are worsened
Solution Approach 1:
The patent segments the single service account into multiple user-specific mirror accounts. Each mirror account is created by copying the enterprise account to the cloud provider and is associated with a specific user, enabling individualized auditing while maintaining automated job execution. This resolves the contradiction by providing both operational simplicity (automated execution) and auditing precision (user-specific tracking).
Solution Approach 2:
The mirror account acts as an intermediary between the user's enterprise account and the cloud cluster access. Instead of users directly using enterprise accounts or a generic service account, the mirror account mediates the authentication and authorization process, enabling both automated operation and precise auditing of individual user activities on cloud clusters.
2Measurement precision
If user credentials are used for cloud cluster access, then authorization precision is improved, but security risk is worsened due to potential exposure of other cloud services
Solution Approach 1:
The patent segments access credentials into user-specific mirror accounts that are isolated from each other and from the original enterprise accounts. Each mirror account has limited scope restricted to cloud cluster data processing only, preventing credential compromise from affecting other cloud services while maintaining precise authorization for the intended purpose.
Solution Approach 2:
The mirror accounts are configured with local quality specific to each user's data processing needs, with permissions scoped only to cloud cluster resources. This localized authorization precision ensures that even if credentials are compromised, the security risk is contained to a specific user's data processing activities and does not expose other cloud services.
3Measurement precision
If enterprise accounts are directly used for cloud access, then authorization precision is improved, but device complexity is worsened due to managing multiple account systems
Solution Approach 1:
The patent creates mirror accounts by copying enterprise accounts to the cloud provider environment. This copying process preserves the authorization precision of original enterprise accounts while simplifying cloud access management, as the mirror accounts automatically inherit permissions and can be managed through existing enterprise identity infrastructure without requiring users to learn new credential systems.
Data Source
AI summary
Methods, systems, and apparatus, including computer programs encoded on computer storage media, for processing data in a multi-tenant system. One of the methods includes receiving a data processing job associated with a user account of a user; determining to launch the data processing job on one or more cloud clusters of a cloud services provider; identifying a mirror account corresponding to the user, wherein the mirror account defines which cloud resources of the cloud services provider the user is permitted to access; obtaining a key for the mirror account; sending a request to launch the data processing job on the one or more cloud clusters, comprising sending data characterizing the data processing job, the mirror account of the user, and the obtained key to the one or more cloud clusters; and receiving output data associated with the data processing job from the one or more cloud clusters.


