Virtual Object Access Control via Personal Spaces

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current virtual computing environments lack an efficient mechanism for users to control access to virtual objects and associated data, making it difficult to share or limit access to these resources.

Innovation Solution

A method is introduced where users can specify personal spaces in a virtual computing environment to encompass virtual objects, allowing them to control access by moving their personal spaces to encompass objects associated with data on remote systems, using credentials stored on those systems to access and share the data with other users.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If users can freely access virtual objects and data in a virtual computing environment, then accessibility and collaboration are improved, but security and data privacy deteriorate

Engineering Contradiction:
ImproveaccessibilityVSAvoiddata security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces personal spaces as intermediary containers between users and virtual objects. These personal spaces act as mediators that control the flow of data and object access. When users enter another user's personal space, authentication mechanisms are triggered, and data sharing is selectively enabled based on user permissions. This intermediary layer resolves the contradiction by providing structured access control that maintains both security and collaboration capabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If users can control access to virtual objects through personal spaces, then data security is improved, but system complexity increases

Engineering Contradiction:
Improvedata securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a nested structure where personal spaces contain virtual objects, which in turn contain data from external systems. This nesting creates hierarchical access control layers: users access objects within personal spaces, which themselves are contained within user profiles, which are linked to external data systems. The nested architecture simplifies security management by organizing access rights in nested containers rather than requiring complex centralized authorization systems.

Inventive Principle:
Principle #7Nested doll (Nesting)

3Reliability

If personal spaces are used to control object access, then access control is improved, but ease of operation deteriorates

Engineering Contradiction:
Improveaccess controlVSAvoiduser interaction
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements self-service mechanisms where users automatically authenticate and grant access rights simply by entering another user's personal space. The system automatically handles credential verification, permission evaluation, and data sharing without requiring manual configuration or complex user interaction. This self-service approach maintains strong access control while significantly improving ease of operation compared to traditional permission-granting systems.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS8280966B2System and method of controlling access to information in a virtual computing environment
Publication Date: 2012.10.02 SAP SE
  • US8280966B2 patent drawing
  • US8280966B2 patent drawing
  • US8280966B2 patent drawing

AI summary

In one embodiment the present invention includes a method comprising specifying personal spaces in the virtual computing environment for first and second users and moving the personal spaces to encompass a virtual object, where the virtual object is associated with data on another system. A message is sent from a virtual server to one of the user's clients to access the data associated with the virtual object from the other system. Credentials necessary for accessing the data are stored on different user's clients, and the credentials are used to authenticate the user and perform the data access. The data associated with the virtual object may then be sent to the other user.