Multitenant Access Control via Tenant-Specific Roles and Licenses
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In multitenant systems, managing access privileges across tenants can become complex for administrators, leading to difficulties in ensuring appropriate access control and resource management.
Innovation Solution
An information processing system is configured to store user accounts and license information for each tenant, including role-based privileges, allowing it to determine whether tasks across tenants are allowed based on user roles and license assignments, thereby enabling secure and controlled access management.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of energy
If a multitenant system is implemented to provide services of multiple enterprises using a single system, then resources and operational costs are reduced, but managing access privileges across tenants becomes complex and difficult
Solution Approach 1:
The system segments access control by introducing tenant-specific roles and license information. Each tenant can have customized role definitions and license assignments, allowing independent management of access privileges per tenant while sharing the underlying system infrastructure. This segmentation resolves the contradiction by enabling multi-tenancy without uniform complex management.
Solution Approach 2:
The patent adds a new dimension to access control by introducing a tenant layer between the user and system resources. Instead of flat user-role assignments, the system now operates with user-tenant-role-license multi-dimensional relationships. This dimensional expansion allows resource sharing while maintaining distinct access control policies for each tenant.
2Device complexity
If traditional access control methods are used without tenant-specific management, then system simplicity is maintained, but appropriate access control and resource management across multiple tenants cannot be ensured
Solution Approach 1:
The system performs preliminary action by pre-defining roles and license information for each tenant before users access resources. Tenant administrators can configure role permissions and license assignments in advance, ensuring that access control policies are established and validated before actual resource access occurs. This preliminary configuration ensures reliable access control while maintaining systematic organization.
Solution Approach 2:
The patent introduces tenant-specific role definitions and license information as intermediary layers between users and system resources. These intermediaries mediate access requests by evaluating both user roles and tenant license assignments, ensuring that access control decisions consider both individual user permissions and organizational resource constraints. This intermediary mechanism enhances access control reliability without requiring complete system redesign.
Data Source
AI summary
An information processing system includes multiple information processing apparatuses for providing a multitenant service. The information processing system is configured: to store a user account for each user belonging to one of a plurality of tenants provided by the multitenant service, the user account including a tenant ID of the tenant, and a role representing privilege of the user; to store license information assigned to each of the tenants, the license information including a license type representing a type of task allowed to be performed by the tenant; to receive a first request, from a first user belonging to a first tenant, for performing a task concerning a second tenant; and to determine, based on the role of the first user and the license information assigned to the first tenant, whether the performing of the task concerning the second tenant is allowed.


