Privileged Role Containers for Cloud Approval Workflows

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Managing access permissions in cloud environments becomes cumbersome and error-prone as the number of users and their required permissions increase, leading to impracticality and potential misconfiguration, especially in large enterprises with diverse departments.

Innovation Solution

Implementing a role container system that includes a set of roles associated with access to resources, with assignment and activation workflows to manage access permissions, utilizing decision points and criteria to ensure accurate and efficient permission management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If individual policy language is used to manage access permissions for each user, then granular control over specific resources is achieved, but system complexity and error-proneness increase significantly as the number of users grows

Engineering Contradiction:
Improvegranular access controlVSAvoidpolicy management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments access permissions into reusable role templates that can be assigned to multiple users. Instead of managing individual policies for each user, the system divides permissions into modular role components (e.g., reader, writer, admin roles) that can be independently configured and combined, reducing the overall complexity of permission management while maintaining granular control.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates universal role templates that can serve multiple users across different departments and contexts. A single role template (e.g., a standard reader role) can be universally applied to numerous users who need the same level of access, eliminating the need to create and maintain separate policies for each user while still providing appropriate granular control for each context.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Measurement precision

If granular policies are defined for each user and role, then precise permission control is achieved, but configuration errors increase and become difficult to manage

Engineering Contradiction:
Improvepermission precisionVSAvoidconfiguration accuracy
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The patent implements preliminary action by pre-configuring validated role templates with precise permissions before they are assigned to users. The role templates are created in advance with carefully defined access levels, and these pre-validated templates are then reused across multiple users. This preliminary configuration ensures permission precision is maintained while reducing configuration errors, as the templates have already been reviewed and validated for correctness.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent incorporates feedback mechanisms that validate role template configurations and provide guidance to administrators during role creation and modification. The system checks for configuration errors, ensures proper permission hierarchies, and provides feedback to prevent common mistakes, thereby maintaining high configuration accuracy even as the number of roles and users increases.

Inventive Principle:
Principle #23Feedback

3Adaptability or versatility

If manual policy configuration is used for each user, then flexibility in assigning specific permissions is achieved, but time consumption and operational overhead increase

Engineering Contradiction:
Improvepermission flexibilityVSAvoidpermission management efficiency
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The patent applies universality by creating role templates that can be universally assigned to multiple users across different departments and contexts. A single role template can serve numerous users with similar access needs, dramatically reducing the time required for permission management while maintaining the flexibility to assign appropriate permissions. The templates can be quickly instantiated and modified as needed, providing both efficiency and adaptability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent uses preliminary action by pre-configuring role templates with common permission patterns before they are needed. These templates are prepared in advance with standard permission sets that can be quickly assigned to users, eliminating the need for manual configuration of each user's permissions from scratch. This preliminary preparation significantly improves permission management efficiency while maintaining flexibility through the ability to customize templates as needed.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12592934B2Managing approval workflows for privileged roles in private label cloud realms
Publication Date: 2026.03.31 ORACLE INT CORP
  • US12592934B2 patent drawing
  • US12592934B2 patent drawing
  • US12592934B2 patent drawing

AI summary

Techniques for access management with role containers are disclosed. Role containers comprise a set of roles such as service roles, application roles, and domain roles. A role container can be assigned to an operator, or a group of operators, using an assignment workflow and can then be activated using an activation workflow. Roles in the role container may include requestable roles and conditional roles. By providing collections of roles in role containers, management can be facilitated on a user or group basis.