Tenant Unification Security Level Automation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

When unifying multiple tenants in a cloud service system, the process often results in security issues due to differing security levels among users, leading to increased burden in changing settings and potential security troubles if low-security users are unified without consideration.

Innovation Solution

A management apparatus with a unification policy setting unit and security level setting unit that uses authentication levels to set security levels for users in a unified group, ensuring consistent handling and adaptive security settings based on pre-unification authentication levels.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If users with different security levels are unified into one group without consideration, then the unification process is simple and fast, but security troubles occur and security levels become inconsistent

Engineering Contradiction:
Improveunification speedVSAvoidsecurity consistency
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent applies preliminary action by determining the security levels of users from different tenants before unification. The management apparatus determines security levels based on authentication levels in advance, and sets appropriate security levels after unification according to pre-established unification policies, preventing security issues before they occur.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent changes the parameter of security level assignment from manual post-unification configuration to automated determination based on authentication levels. The management apparatus automatically determines and sets security levels by referencing authentication levels and unification policies, ensuring consistent security management across unified tenants.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If security levels are changed on a per user basis after unification, then security consistency is improved, but the burden in changing settings increases with the number of users

Engineering Contradiction:
Improvesecurity consistencyVSAvoidsettings management burden
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service by enabling the management apparatus to automatically determine and set security levels for all users after unification. The system uses unification policies and authentication levels to automatically assign security levels without requiring manual intervention for each user, reducing the settings management burden while maintaining security consistency.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent transforms the security level management process from manual per-user configuration to automated parameter-based assignment. By changing security levels based on authentication levels and unification policies, the system efficiently manages security settings for large numbers of users without increasing operational complexity.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If manual security level adjustment is performed after unification, then security control is precise, but time consumption increases significantly

Engineering Contradiction:
Improvesecurity control precisionVSAvoidtime for security settings
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The management apparatus performs self-service by automatically determining security levels based on authentication levels and unification policies. This eliminates the need for manual security level adjustment for each user, significantly reducing the time required for security settings while maintaining precise security control through policy-based automation.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary determination of security levels based on authentication levels before final unification completion. By establishing unification policies in advance and automatically applying them, the system prepares security level assignments beforehand, eliminating time-consuming manual adjustments after unification.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11568040B2Management apparatus and non-transitory computer readable medium for setting security levels of users in group resulting from unification
Publication Date: 2023.01.31 FUJIFILM BUSINESS INNOVATION CORP
  • US11568040B2 patent drawing
  • US11568040B2 patent drawing
  • US11568040B2 patent drawing

AI summary

A management apparatus includes a memory, a unification policy setting unit, and a security level setting unit. The memory stores, for each of a user belonging to a first group and a user belonging to a second group, an authentication level of a domain assigned to a corresponding one of the users. The unification policy setting unit sets a unification policy that specifies a relationship between the authentication level and a security level for a state after unification. The security level setting unit sets the security level in a case where the first group and the second group undergo the unification into a third group. The security level is set for each of the users belonging to the third group by using the authentication level and the unification policy.