Permission Set Validation for Cloud User Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing cloud computing systems face challenges in efficiently managing and assigning permissions to a large number of users, as different users require varying levels and types of access, leading to administrative overhead and complexity in ensuring compliance with user licenses and constraints.
Innovation Solution
The implementation of permission sets that can be assigned to users, allowing for scalable and efficient management of permissions through a permission server that validates assignments against user licenses and constraints, enabling administrators to create and modify permissions sets while ensuring compliance with user licenses and constraints, thereby reducing administrative burden.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If manual permission assignment is used for each user, then individual permission control is achieved, but administrative time and complexity increase significantly
Solution Approach 1:
The patent combines multiple individual permissions into grouped permission sets that can be assigned to users collectively. Instead of assigning permissions one-by-one to each user, administrators can assign entire permission sets containing multiple related permissions, significantly reducing the time and effort required for permission management while maintaining granular control over what each permission set entails.
Solution Approach 2:
The patent creates permission sets that can be universally assigned to multiple users across different licenses. A single permission set can serve multiple users with different user licenses, allowing the same collection of permissions to be reused across the system. This multi-functional approach eliminates the need to create and manage separate permission assignments for each user individually.
2Productivity
If permission sets are assigned to multiple users with different licenses, then scalability is improved, but compliance validation complexity increases
Solution Approach 1:
The patent performs compliance validation in advance by checking whether a permission set is compatible with a user license before assignment. The system validates that all permissions within a permission set are permitted under the target user license, preventing compliance violations before they occur. This preliminary validation approach simplifies the assignment process by ensuring compliance upfront rather than requiring complex ongoing validation.
Solution Approach 2:
The patent implements an error message system that provides feedback to administrators when a permission set cannot be assigned to a user license due to compliance issues. The system checks compatibility and returns specific error messages indicating which permissions cause the violation, guiding administrators to modify the permission set or select a different license. This feedback mechanism simplifies compliance management by making the validation process transparent and actionable.
3Reliability
If individual permissions are managed for each user, then precise control is achieved, but administrative overhead increases
Solution Approach 1:
The patent merges multiple individual permissions into organized permission sets that maintain precise control over system resources. Each permission set contains a specific collection of permissions that work together to provide a coherent access level. This merging approach preserves the precision of individual permission control while reducing administrative overhead by allowing bulk assignment of related permissions as a unified group.
Solution Approach 2:
The patent segments the overall permission management system into hierarchical levels: user licenses, permission sets, and individual permissions. This segmentation allows administrators to manage permissions at the permission set level for routine operations while maintaining the ability to drill down to individual permissions when needed. The segmented structure reduces overhead by providing appropriate abstraction levels for different management tasks.
Data Source
AI summary
Disclosed are methods, apparatus, systems, and computer-readable storage media for modifying permission sets and validating permission set assignments to users. In some implementations, a computing device receives a request to create a permission set containing one or more permissions and assign the permission set to a first user. The first user is associated with a first user constraint that defines a first group of permissions available to the first user. The computing device may determine that the permission set to be assigned to the first user does not violate the first user constraint, and may assign the permission set to the first user.


