Tenant-Aware Device Access Control via Group Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current cloud-based management systems lack efficient control over device usage across multiple tenant systems, leading to inconsistent access and usage permissions, particularly when integrating or dividing these systems.
Innovation Solution
A management apparatus with user and device information management units, along with a controller, that associates user identification information with group memberships and device permissions, enabling controlled device usage based on group affiliations, facilitating seamless integration and division of tenant systems while maintaining access permissions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If cloud-based management systems are used to manage devices across multiple tenant systems, then device accessibility and service flexibility are improved, but control consistency and permission management become problematic during system integration or division
Solution Approach 1:
The management system is segmented into multiple tenant systems, each with independent group and permission management. This allows each tenant system to maintain its own access control policies while being part of the larger cloud-based management infrastructure, resolving the contradiction between flexibility and consistency.
Solution Approach 2:
Group information and device permissions are pre-configured and stored in the management apparatus before system integration or division occurs. This preliminary setup ensures that when tenant systems are integrated or divided, the access control relationships are already established and maintained consistently across the reorganized structure.
2Adaptability or versatility
If device permissions are managed centrally in cloud-based systems, then service flexibility is improved, but control over device usage across multiple tenant systems becomes inconsistent
Solution Approach 1:
Permission management is segmented by tenant system and group, allowing each tenant to independently manage device permissions for their specific users and groups. This segmentation maintains service flexibility at the cloud level while simplifying permission management at the tenant level through localized control.
Solution Approach 2:
The system adds a tenant system dimension to the traditional user-device permission model. Permissions are now managed in three dimensions: tenant system, group, and device. This multi-dimensional approach allows flexible service delivery while simplifying operation through structured, hierarchical permission control.
3Reliability
If group information is managed in association with user identification, then user access control is improved, but system complexity increases during tenant system integration or division
Solution Approach 1:
Group information is segmented by tenant system, with each tenant maintaining its own group definitions and user associations. This segmentation maintains reliable user access control within each tenant while reducing overall system complexity during integration or division, as each tenant's group structure remains independent and manageable.
Solution Approach 2:
The group management mechanism serves multiple functions: it controls user access to devices, defines permission scopes, and maintains user relationships across tenant systems. This universal group structure reduces complexity by providing a single, consistent mechanism that handles multiple access control requirements simultaneously.
Data Source
AI summary
A management apparatus includes a user information management unit, a device information management unit, and a controller. The user information management unit manages information about groups to which individual users belong, in association with user identification information identifying the users. The device information management unit manages, for one device or each of plural devices, information about a main group to which the device belongs and information about a sub-group for which use of the device is permitted, in association with each other. The controller controls, when accepting a request for using a device from an information terminal, use of the device in accordance with whether or not information about a group managed in association with user identification information of a user who operates the information terminal is included in information about the main group or sub-group managed in association with the device.


