Organization Account Identity Projection for Cloud Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Large organizations face complex management challenges in ensuring users are associated with the appropriate accounts for accessing resources in cloud environments, leading to potential errors in access permissions and increased resource overhead.
Innovation Solution
Implementing organization-level identity management by associating users with organization accounts or virtual identities that can project access to sub-accounts within an organizational hierarchy, simplifying the management of user identities across multiple resource accounts and reducing the need for multiple credentials.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If users are associated with individual resource accounts for each service, then access permissions can be precisely controlled, but management complexity and resource overhead increase significantly
Solution Approach 1:
The patent segments identity management into two distinct layers: organization accounts (representing the entity) and resource accounts (representing specific services). This segmentation allows the organization account to be shared across multiple resource accounts, eliminating the need for individual user credentials for each service while maintaining precise access control through role-based permissions at the resource account level.
Solution Approach 2:
The patent introduces organization accounts as an intermediary layer between users and resource accounts. Instead of direct user-resource account associations, the organization account acts as a mediator that can be attached to multiple resource accounts, simplifying identity management while enabling fine-grained access control through the attachment hierarchy and role-based permissions.
2Reliability
If multiple credentials are required for different services, then security is improved, but ease of operation deteriorates
Solution Approach 1:
The organization account serves multiple functions simultaneously: it represents the organizational entity, provides authentication credentials for accessing multiple resource accounts, and enables role-based access control across different services. This multi-functionality eliminates the need for separate credentials for each service while maintaining security through the attachment hierarchy and permission policies.
3Manufacturing precision
If individual user accounts are created for each resource account, then access control precision is improved, but resource overhead increases
Solution Approach 1:
The patent merges multiple user identities into a single organization account that can be attached to multiple resource accounts. Instead of creating separate user accounts for each service, the organization account is combined with resource accounts through attachments, maintaining precise access control through role-based permissions while reducing the total number of accounts needed.
Data Source
AI summary
User identities can managed at an organization level, instead of across multiple individual resource accounts. In a resource provider environment, access to various resources and services may require users to have identities with specific resource accounts. Users can instead be associated with organization accounts, or virtual accounts that are not associated with specific resources or services. The organization accounts are attached at the appropriate location(s) in an organizational hierarchy. A user having an organization account can project the identity in any sub-account in the organization hierarchy. This can include any lower-level resource account, or can child accounts under a relevant branch of the hierarchy. A user can validate against the organization account, and receive access to the relevant service or resources using the identity projected in the corresponding resource account.


