Multitenant Access Control via Tenant-Specific Roles and Licenses

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In multitenant systems, managing access privileges across tenants can become complex for administrators, leading to difficulties in ensuring appropriate access control and resource management.

Innovation Solution

An information processing system is configured to store user accounts and license information for each tenant, including role-based privileges, allowing it to determine whether tasks across tenants are allowed based on user roles and license assignments, thereby enabling secure and controlled access management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of energy

If a multitenant system is implemented to provide services of multiple enterprises using a single system, then resources and operational costs are reduced, but managing access privileges across tenants becomes complex and difficult

Engineering Contradiction:
Improveoperational costVSAvoidaccess privilege management complexity
Core Design Contradiction:
Loss of energyVSDevice complexity

Solution Approach 1:

The system segments access control by introducing tenant-specific roles and license information. Each tenant can have customized role definitions and license assignments, allowing independent management of access privileges per tenant while sharing the underlying system infrastructure. This segmentation resolves the contradiction by enabling multi-tenancy without uniform complex management.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent adds a new dimension to access control by introducing a tenant layer between the user and system resources. Instead of flat user-role assignments, the system now operates with user-tenant-role-license multi-dimensional relationships. This dimensional expansion allows resource sharing while maintaining distinct access control policies for each tenant.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Device complexity

If traditional access control methods are used without tenant-specific management, then system simplicity is maintained, but appropriate access control and resource management across multiple tenants cannot be ensured

Engineering Contradiction:
Improvesystem structure simplicityVSAvoidaccess control reliability
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The system performs preliminary action by pre-defining roles and license information for each tenant before users access resources. Tenant administrators can configure role permissions and license assignments in advance, ensuring that access control policies are established and validated before actual resource access occurs. This preliminary configuration ensures reliable access control while maintaining systematic organization.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces tenant-specific role definitions and license information as intermediary layers between users and system resources. These intermediaries mediate access requests by evaluating both user roles and tenant license assignments, ensuring that access control decisions consider both individual user permissions and organizational resource constraints. This intermediary mechanism enhances access control reliability without requiring complete system redesign.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10803161B2Information processing system, information processing method, and information processing apparatus
Publication Date: 2020.10.13 RICOH CO LTD
  • US10803161B2 patent drawing
  • US10803161B2 patent drawing
  • US10803161B2 patent drawing

AI summary

An information processing system includes multiple information processing apparatuses for providing a multitenant service. The information processing system is configured: to store a user account for each user belonging to one of a plurality of tenants provided by the multitenant service, the user account including a tenant ID of the tenant, and a role representing privilege of the user; to store license information assigned to each of the tenants, the license information including a license type representing a type of task allowed to be performed by the tenant; to receive a first request, from a first user belonging to a first tenant, for performing a task concerning a second tenant; and to determine, based on the role of the first user and the license information assigned to the first tenant, whether the performing of the task concerning the second tenant is allowed.