Multi-Environment Policy Access Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional access management systems lack operational features for external-customer computing environments, providing limited control and visibility, and fail to account for diverse computing environments and scenarios, leading to inefficient access provisioning operations.

Innovation Solution

A multi-environment policy is introduced, configurable to define rules for provider-controlled and customer-controlled computing environments, using access vectors to manage access provisioning operations, providing managed control and visibility for integrated access management across different types of computing environments.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If conventional access management systems are used for internal resources, then access control is provided, but operational features for external-customer computing environments are lacking

Engineering Contradiction:
Improveadaptability to different computing environmentsVSAvoidoperational features for external customers
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The access management system is enhanced to provide universal access control capabilities across multiple computing environments (internal and external). The system maintains a unified policy framework that can be configured to work with different environment types, eliminating the need for separate access management systems while preserving environment-specific operational features through configurable policies

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If access management is provided for diverse computing environments, then comprehensive control is achieved, but system complexity increases

Engineering Contradiction:
Improvesupport for different computing environmentsVSAvoidaccess management system complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The access management system is segmented into modular components: a core policy engine that handles unified access control logic, and environment-specific configuration modules that can be selectively activated. This segmentation allows the system to support diverse computing environments without requiring all components to be active simultaneously, thereby managing complexity while maintaining versatility

Inventive Principle:
Principle #1Segmentation

3Ease of operation

If traditional access management approaches are used, then simple implementation is achieved, but control and visibility for external customers is limited

Engineering Contradiction:
Improvecontrol and visibility for customersVSAvoidaccess management infrastructure
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

An intermediary access management layer is introduced between customers and computing environments. This intermediary provides enhanced control and visibility to external customers through standardized interfaces while maintaining compatibility with existing infrastructure, thereby improving customer control without proportionally increasing infrastructure complexity

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20230328110A1Access management system with a multi-environment policy
Publication Date: 2023.10.12 MICROSOFT TECHNOLOGY LICENSING LLC
  • US20230328110A1 patent drawing
  • US20230328110A1 patent drawing
  • US20230328110A1 patent drawing

AI summary

Methods, systems, and computer storage media for providing access to computing environments based on a multi-environment policy are provided. The a multi-environment policy is configurable to define rules that have provider-controlled and customer-controlled computing environment parameters for approving access to provider-controlled computing environments and customer-controlled computing environments. In operation, a request associated a computing environment are received. The computing environment is associated with a multi-environment policy. The multi-environment policy is configurable to define the rules based on access vectors having grouped computing environment aspects for control and visibility associated with accessing computing environments. Based on the request, a determination whether the request is for a provider-controlled or a customer-controlled computing environment is made. Based on the multi-environment policy, approval-request parameters of an approval-request are communicated to receive approval-request response values. And, based on receiving the approval-request response values, a request response indicating approval or denial of the request is communicated.