Role-Based Resource Access Control in Virtualization Systems
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In virtualization technology systems, access control for shared resources is challenging due to complex relationships between resources, making it difficult to set roles for shared resources and ensuring secure operation.
Innovation Solution
A computer system with resource management information and resource group management information is used to determine access permissions for resources, allowing control of resource access by user groups while maintaining security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If access control using roles is not performed in dedicated management software, then higher administrator can access storage resources freely, but security is compromised and unauthorized operations may occur
Solution Approach 1:
The patent segments storage resources into distinct resource groups (first resource group for upper management software, second resource group for dedicated management software) and assigns different access control policies to each group. This allows the higher administrator to have different permission levels for different resource groups, enabling security through segmentation while maintaining operational flexibility.
Solution Approach 2:
The patent applies local quality by setting different access control characteristics for different resource groups. The first resource group has access control enabled with specific role-based permissions, while the second resource group has different access control settings. This allows security measures to be applied locally where needed rather than uniformly across all resources.
2Reliability
If roles are set for shared resources in virtualization systems, then access control can be enforced, but the complex relationships between resources make role setting difficult
Solution Approach 1:
The patent simplifies the complex resource relationships by segmenting resources into distinct resource groups with clear boundaries. Each resource group has defined access control policies, which reduces the complexity of setting roles for individual shared resources. The segmentation approach transforms a complex many-to-many resource relationship into manageable group-based relationships.
Solution Approach 2:
The patent creates a universal access control mechanism that works across different types of resources (storage resources, virtualization resources) by using a common resource group framework. This multi-functional approach allows the same access control system to handle diverse resource types without requiring separate role-setting mechanisms for each resource type.
3Productivity
If upper administrator uses dedicated management software directly, then management can be performed when upper management software stops, but access control is not performed and erroneous operations may occur
Solution Approach 1:
The patent segments the system into upper management software and dedicated management software with distinct resource groups. This segmentation allows the higher administrator to access the dedicated management software for continuous operation while simultaneously applying access control through resource group permissions to prevent erroneous operations. The segmentation enables both productivity and reliability.
Solution Approach 2:
The patent introduces resource group management information as an intermediary layer between the higher administrator and storage resources. This intermediary enforces access control policies even when accessing through dedicated management software, acting as a mediator that maintains operation safety while allowing management continuity.
Data Source
AI summary
A computer system having a plurality of resources used for a source program includes: resource management information for storing information in which each of the resources is associated with a resource group; and resource group management information for storing information in which a user capable of using the resource group is associated with the source program. When receiving a request designating the resource related to a user who uses the source program from the source program, a control unit uses the resource group management information and the resource management information to determine whether access to the resource related to the request is permitted.


