Mirror Account Segmentation for Multi-Tenant Cloud Identity

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In multi-tenant environments, managing user identities for data processing in hybrid on-premises and cloud architectures is challenging, particularly when unattended tasks on cloud clusters require access to multiple services, as single service accounts complicate auditing and authorization, and expose user data to security risks.

Innovation Solution

The creation and use of mirror accounts, which are unique to each user and mirror their enterprise accounts, allowing for transparent authorization, authentication, and auditing of data processing jobs on cloud clusters without exposing access to other cloud services, thereby limiting potential security breaches.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a single service account is used for all users to access cloud clusters, then ease of operation is improved, but auditing precision and security are worsened

Engineering Contradiction:
Improveease of operationVSAvoidauditing precision
Core Design Contradiction:
Ease of operationVSMeasurement precision

Solution Approach 1:

The patent segments the single service account into multiple user-specific mirror accounts. Each mirror account is created by copying the enterprise account to the cloud provider and is associated with a specific user, enabling individualized auditing while maintaining automated job execution. This resolves the contradiction by providing both operational simplicity (automated execution) and auditing precision (user-specific tracking).

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The mirror account acts as an intermediary between the user's enterprise account and the cloud cluster access. Instead of users directly using enterprise accounts or a generic service account, the mirror account mediates the authentication and authorization process, enabling both automated operation and precise auditing of individual user activities on cloud clusters.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If user credentials are used for cloud cluster access, then authorization precision is improved, but security risk is worsened due to potential exposure of other cloud services

Engineering Contradiction:
Improveauthorization precisionVSAvoidsecurity risk
Core Design Contradiction:
Measurement precisionVSObject-affected harmful factors

Solution Approach 1:

The patent segments access credentials into user-specific mirror accounts that are isolated from each other and from the original enterprise accounts. Each mirror account has limited scope restricted to cloud cluster data processing only, preventing credential compromise from affecting other cloud services while maintaining precise authorization for the intended purpose.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The mirror accounts are configured with local quality specific to each user's data processing needs, with permissions scoped only to cloud cluster resources. This localized authorization precision ensures that even if credentials are compromised, the security risk is contained to a specific user's data processing activities and does not expose other cloud services.

Inventive Principle:
Principle #3Local quality

3Measurement precision

If enterprise accounts are directly used for cloud access, then authorization precision is improved, but device complexity is worsened due to managing multiple account systems

Engineering Contradiction:
Improveauthorization precisionVSAvoiddevice complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent creates mirror accounts by copying enterprise accounts to the cloud provider environment. This copying process preserves the authorization precision of original enterprise accounts while simplifying cloud access management, as the mirror accounts automatically inherit permissions and can be managed through existing enterprise identity infrastructure without requiring users to learn new credential systems.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS11349846B2Managing user identities in a managed multi-tenant service
Publication Date: 2022.05.31 X CORP
  • US11349846B2 patent drawing
  • US11349846B2 patent drawing
  • US11349846B2 patent drawing

AI summary

Methods, systems, and apparatus, including computer programs encoded on computer storage media, for processing data in a multi-tenant system. One of the methods includes receiving a data processing job associated with a user account of a user; determining to launch the data processing job on one or more cloud clusters of a cloud services provider; identifying a mirror account corresponding to the user, wherein the mirror account defines which cloud resources of the cloud services provider the user is permitted to access; obtaining a key for the mirror account; sending a request to launch the data processing job on the one or more cloud clusters, comprising sending data characterizing the data processing job, the mirror account of the user, and the obtained key to the one or more cloud clusters; and receiving output data associated with the data processing job from the one or more cloud clusters.