Versioned Access Controls for Data Center Role Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
As data centers grow in scale and complexity, managing and storing increasing amounts of data becomes increasingly costly and complicated, with existing technologies struggling to efficiently manage and store data while maintaining simplicity and reducing storage requirements.
Innovation Solution
Implementing versioned and custom access controls within a configurable workflow service that allows for the management of roles and permissions, enabling flexible and secure access to computing resources, and using a role management service to automatically assign and manage roles for nodes and workflows, ensuring compatibility with evolving resource availability.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Quantity of substance
If data centers grow in scale to store and manage increasing amounts of data, then data storage capacity and management capability are improved, but system complexity and operational costs increase
Solution Approach 1:
The patent segments the monolithic access control system into versioned role definitions that can be independently managed and updated. Each role version encapsulates a specific set of permissions, allowing the system to scale by adding new role versions without restructuring the entire access control framework, thereby managing complexity while supporting growth in data storage capacity
Solution Approach 2:
The patent applies parameter changes by versioning role definitions with version identifiers. This allows the system to evolve access control parameters (permissions, resources, conditions) over time without breaking existing workflows. Each version represents a parameter snapshot that can be applied to multiple workflows, enabling scalable management of access controls as data center complexity increases
2Reliability
If access control policies are updated to improve security, then security level is improved, but compatibility with existing workflows may be compromised
Solution Approach 1:
The patent implements preliminary action by creating and storing multiple versions of role definitions before deploying security updates. This allows administrators to prepare new secure configurations in advance, test them, and then selectively apply them to workflows. Existing workflows continue to use their compatible role versions until explicitly updated, preventing compatibility issues while enabling progressive security improvements
Solution Approach 2:
The patent uses copying by creating role version copies that can be referenced by multiple workflows. When a role is updated, the system creates a new version copy rather than modifying the original in place. This allows existing workflows to continue referencing the old version copy, maintaining compatibility, while new workflows can adopt the updated version, balancing security improvements with system adaptability
3Adaptability or versatility
If role permissions are expanded to provide more flexible access control, then access control flexibility is improved, but system complexity increases
Solution Approach 1:
The patent applies universality by designing role definitions as multi-functional entities that can serve multiple workflows across different versions. A single role version can be assigned to numerous workflows, and workflows can reference different role versions based on their specific needs. This universal structure provides flexible access control without requiring separate complex configurations for each workflow, managing role management complexity while enhancing flexibility
Data Source
AI summary
Methods and systems for implementing versioned access controls are disclosed. A first task is added to a first workflow with a first version of a default role. A second version of the default role is generated after the first task is added. A second task is added to a second workflow with the second version of the default role. The first version and the second version each comprise one or more permissions for using one or more computing resources. The first task is performed using the permissions in the first version of the default role. The second task is performed using the permissions in the second version of the default role.


