Organization Account Identity Projection for Cloud Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Large organizations face complex management challenges in ensuring users are associated with the appropriate accounts for accessing resources in cloud environments, leading to potential errors in access permissions and increased resource overhead.

Innovation Solution

Implementing organization-level identity management by associating users with organization accounts or virtual identities that can project access to sub-accounts within an organizational hierarchy, simplifying the management of user identities across multiple resource accounts and reducing the need for multiple credentials.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If users are associated with individual resource accounts for each service, then access permissions can be precisely controlled, but management complexity and resource overhead increase significantly

Engineering Contradiction:
Improveaccess permission controlVSAvoididentity management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments identity management into two distinct layers: organization accounts (representing the entity) and resource accounts (representing specific services). This segmentation allows the organization account to be shared across multiple resource accounts, eliminating the need for individual user credentials for each service while maintaining precise access control through role-based permissions at the resource account level.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces organization accounts as an intermediary layer between users and resource accounts. Instead of direct user-resource account associations, the organization account acts as a mediator that can be attached to multiple resource accounts, simplifying identity management while enabling fine-grained access control through the attachment hierarchy and role-based permissions.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If multiple credentials are required for different services, then security is improved, but ease of operation deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoiduser operation simplicity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The organization account serves multiple functions simultaneously: it represents the organizational entity, provides authentication credentials for accessing multiple resource accounts, and enables role-based access control across different services. This multi-functionality eliminates the need for separate credentials for each service while maintaining security through the attachment hierarchy and permission policies.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Manufacturing precision

If individual user accounts are created for each resource account, then access control precision is improved, but resource overhead increases

Engineering Contradiction:
Improveaccess control precisionVSAvoidnumber of accounts
Core Design Contradiction:
Manufacturing precisionVSQuantity of substance

Solution Approach 1:

The patent merges multiple user identities into a single organization account that can be attached to multiple resource accounts. Instead of creating separate user accounts for each service, the organization account is combined with resource accounts through attachments, maintaining precise access control through role-based permissions while reducing the total number of accounts needed.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS11962511B2Organization level identity management
Publication Date: 2024.04.16 AMAZON TECH INC
  • US11962511B2 patent drawing
  • US11962511B2 patent drawing
  • US11962511B2 patent drawing

AI summary

User identities can managed at an organization level, instead of across multiple individual resource accounts. In a resource provider environment, access to various resources and services may require users to have identities with specific resource accounts. Users can instead be associated with organization accounts, or virtual accounts that are not associated with specific resources or services. The organization accounts are attached at the appropriate location(s) in an organizational hierarchy. A user having an organization account can project the identity in any sub-account in the organization hierarchy. This can include any lower-level resource account, or can child accounts under a relevant branch of the hierarchy. A user can validate against the organization account, and receive access to the relevant service or resources using the identity projected in the corresponding resource account.