Resource Container Service for Multi-Account Policy Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Managing large sets of computing resources with varying access policies across multiple customer accounts is complex, especially when handling failure modes and enabling resource sharing among customers, as existing solutions require manual workflows and lack efficient policy management across multiple accounts.
Innovation Solution
A resource container service that allows customers to create and manage resource containers, which are data structures that associate various computing resources with policies, enabling access control and sharing across multiple customer accounts through an API, allowing policies to span across multiple accounts and resources.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If manual workflows are used to manage access policies for large sets of resources across multiple customer accounts, then individual resource control is maintained, but the complexity of policy management increases significantly and productivity decreases
Solution Approach 1:
The patent introduces resource containers as intermediary objects that aggregate multiple resources and apply access policies at the container level rather than individually on each resource. This intermediary layer simplifies policy management by providing a single point of control for managing access to large sets of resources across multiple customer accounts, reducing the operational complexity while maintaining individual resource control through the container abstraction.
2Adaptability or versatility
If resources are shared among multiple customer accounts with varying access policies, then collaboration capability is enhanced, but the device complexity for managing policies across accounts increases
Solution Approach 1:
The patent segments the policy management system into hierarchical levels: resource containers at the aggregation level and individual resources within containers. Each container can have its own access policies that apply to all contained resources, while individual resources can also have specific policies. This segmentation allows resources to be shared among multiple customer accounts with varying access policies without requiring a monolithic complex policy management system, as policies can be defined and enforced at the appropriate hierarchical level.
3Manufacturing precision
If individual access policies are defined for each resource in large sets, then fine-grained control is achieved, but the time required to manage and update policies increases
Solution Approach 1:
The patent merges the management of access policies for multiple resources by allowing a single access policy to be applied to an entire resource container that holds multiple resources. This combining approach enables fine-grained access control precision to be maintained through container-level policies while dramatically reducing the time required to manage and update policies, as changes can be propagated to all contained resources through the container rather than requiring individual updates to each resource.
Data Source
AI summary
A set of operations is performed to cause a resource accessible to a first set of entities to also be accessible to a member of a second set of entities, where the set of operations, as a result of being executed, causes a processor to create a project to associate with a set of resources, associate a policy that controls access to the set of resources with the projects, associate the resource with the set of resources of the project, and associate the member of the second set of entities with the project. A request is obtained from the member of the second set of entities to access the resource. The member of the second set of entities is determine to be authorized to access the resource based on the policy. The member of the second set of entities is allowed to obtain access to the resource.


