Nested Resource Identity Management for Cloud Tenancies

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing approaches for enabling a resource in a service tenancy to access a customer-owned resource in a different tenancy require exposing internal resource identities, which can compromise security and are cumbersome, involving the need for complex cross-tenancy policies.

Innovation Solution

A nested resource principals management system that allows a resource in a service tenancy to access a customer-owned resource in a customer tenancy without using a cross-tenancy policy by obtaining and using the resource principal identity of a higher-level resource, enabling seamless access through a generic policy associated with the higher-level resource.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If cross-tenancy policies are used to enable resource access between service tenancy and customer tenancy, then resource access capability is improved, but device complexity and security risk increase

Engineering Contradiction:
Improveresource access capabilityVSAvoidpolicy complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces a nested resource principal mechanism as an intermediary that automatically mediates access between service tenancy resources and customer tenancy resources. Instead of requiring explicit cross-tenancy policies, the system uses the nested resource principal (inherited from the higher-level resource) as a mediator to enable access control, thereby reducing policy complexity while maintaining access capability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The nested resource principal mechanism enables self-service access control where the service tenancy resource automatically inherits and uses the resource principal from its higher-level resource in the customer tenancy. This eliminates the need for manual policy configuration by customers, allowing the system to automatically manage cross-tenancy access based on the inherited principal.

Inventive Principle:
Principle #25Self-service

2Adaptability or versatility

If internal resource identities are exposed to enable cross-tenancy access, then resource sharing capability is improved, but security is compromised

Engineering Contradiction:
Improveresource sharing capabilityVSAvoidsecurity risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent uses copying of the resource principal identity rather than exposing internal resource identities. The nested resource principal is a copy of the higher-level resource's identity that is inherited and used for access control. This allows resource sharing capability while maintaining security, as the copied principal does not expose the actual internal identities of service tenancy resources to the customer tenancy administrators.

Inventive Principle:
Principle #26Copying

3Manufacturing precision

If detailed cross-tenancy policies are written to control resource access, then access control precision is improved, but ease of operation deteriorates

Engineering Contradiction:
Improveaccess control precisionVSAvoidpolicy configuration ease
Core Design Contradiction:
Manufacturing precisionVSEase of operation

Solution Approach 1:

The patent segments the access control mechanism into two parts: the higher-level resource policy (written by customer) and the nested resource principal inheritance (automatic). This segmentation allows customers to write precise access control policies for their higher-level resources while the system automatically handles the inheritance and application of these policies to nested service tenancy resources, greatly improving ease of operation while maintaining precision.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS20250097302A1Nested resource identity management for cloud resources
Publication Date: 2025.03.20 ORACLE INT CORP
  • US20250097302A1 patent drawing
  • US20250097302A1 patent drawing
  • US20250097302A1 patent drawing

AI summary

A system is disclosed that includes capabilities by which a nested sub-resource residing in a service tenancy can access a customer-owned resource residing in a customer tenancy without the use of a cross-tenant policy. The disclosed system provides the ability for a nested sub-resource residing in a service tenancy to obtain the resource principal identity of a higher-level resource residing in the customer tenancy and use the identity of the higher-level resource to access a customer-owned resource residing in the customer tenancy. Using the resource principal identity of its higher-level resource, the sub-resource can access a customer-owned resource that resides in a customer tenancy in a seamless way without having to write a cross-tenancy policy statement that provides permission to the sub-resource to access the customer-owned resource.