Tenant User Management via Identity Provider Group Mapping

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional systems require tedious manual configuration of user roles, permissions, and capabilities for each user within a cloud-based network architecture, making it inefficient to manage groups of tenant users as a single unit, especially when integrating with external identity providers.

Innovation Solution

A method for mapping a group of users to a tenant within a cluster, assigning the same roles, capabilities, and permissions, and synchronizing with an external identity provider user group, allowing efficient management of user groups across multiple clusters.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If manual configuration of user roles and permissions is performed for each user, then user access control can be precisely configured, but the configuration process becomes tedious and time-consuming

Engineering Contradiction:
ImproveUser configuration easeVSAvoidConfiguration time
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The patent combines multiple users into a tenant group that is mapped to a single tenant, allowing bulk configuration of roles and permissions. Instead of configuring each user individually, the system applies uniform roles and permissions to the entire tenant group, significantly reducing configuration time and effort while maintaining precise access control.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The tenant group mapping mechanism provides universal applicability by allowing a single configuration to affect multiple users simultaneously. The system enables one-time configuration of roles and permissions that automatically apply to all users in the mapped tenant group, eliminating the need for repeated individual configurations.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Manufacturing precision

If each user is configured individually, then precise role and permission assignment is possible, but system complexity increases

Engineering Contradiction:
ImproveRole assignment precisionVSAvoidSystem configuration complexity
Core Design Contradiction:
Manufacturing precisionVSDevice complexity

Solution Approach 1:

The system merges individual user configurations into a unified tenant group mapping. By mapping a tenant group to a tenant, the system maintains precise role and permission assignment while reducing configuration complexity through bulk operations. The mapping mechanism preserves the ability to assign specific roles to specific user groups without requiring individual user-level configuration for each member.

Inventive Principle:
Principle #5Merging (Combining)

3Productivity

If tenant groups are mapped to tenants, then group management efficiency improves, but the system requires integration with identity providers

Engineering Contradiction:
ImproveUser management productivityVSAvoidSystem integration requirement
Core Design Contradiction:
ProductivityVSAdaptability or versatility

Solution Approach 1:

The patent introduces an identity provider as an intermediary component that facilitates tenant group mapping. The identity provider acts as a mediator between user authentication systems and the cluster management system, enabling seamless integration. This intermediary approach allows the system to leverage existing identity management infrastructure while achieving improved group management efficiency through tenant group mapping.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20250294030A1Managing Tenant Users in Coordination with Identity Provider
Publication Date: 2025.09.18 RAKUTEN SYMPHONY INC
  • US20250294030A1 patent drawing
  • US20250294030A1 patent drawing
  • US20250294030A1 patent drawing

AI summary

Systems and methods for mapping users to tenants within a containerized workload management architecture. A method includes identifying a tenant group comprising a plurality of users. The method includes mapping the tenant group to a tenant and adding the tenant to a cluster, wherein the cluster comprises compute resources for executing workloads. The method is such that each of the plurality of users within the tenant group is assigned a same role and same permissions within the cluster.