A multi-tenant cloud platform management system based on a paas platform
By using a multi-tenant cloud platform management system based on the PaaS platform, tenant permissions are configured and managed in a unified manner, which solves the problem of repetitive development in existing technologies, enables convenient deployment of tenant applications and multi-tenant transaction clearing and settlement, and improves development efficiency and system stability.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- E-BUY INFORMATION TECH (SHANGHAI) CO LTD
- Filing Date
- 2022-09-06
- Publication Date
- 2026-06-05
Smart Images

Figure CN115578193B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of tenant service technology on the Internet, and in particular to a multi-tenant cloud platform management system based on the PaaS platform. Background Technology
[0002] With the development of cloud computing technology, deploying applications using a PaaS (Platform-as-a-Service) platform has become a preferred solution. A PaaS platform is a business model that provides the runtime and development environment of application services as a service. A PaaS platform has multiple tenants, and a software product can be installed within a single tenant environment (or considered as a single tenant). A single software product may consist of multiple applications. These multiple applications require access control. Existing application access control logic mainly includes the following steps: 1) The authorization system generates an authorization file; 2) The software delivery personnel import the authorization file into the application; 3) The application parses the authorization file and generates a deployment environment summary; 4) The software delivery personnel import the deployment environment summary into the authorization system and generate an authorization license file; 5) The software delivery personnel import the authorization license file into the application, and authorization is successful. Existing access control schemes require the application itself to implement operations such as parsing the authorization file and generating the deployment environment summary to achieve access control. Therefore, each application needs to develop the same module code to implement access control. When there are many applications, this repetitive work is a serious waste of resources in the context of agile development and rapid delivery. Each application requires a corresponding amount of manpower to do the same work, making it impossible for software developers to focus on the business domain.
[0003] Providing a one-stop cloud-to-end solution for tenant-level development, testing, operation and maintenance can effectively reduce technical barriers, reduce R&D costs, improve development efficiency, and help enterprises quickly build stable and high-quality PaaS platform applications. In view of this, this application aims to add multi-tenancy technology to the existing PaaS platform to solve the problems existing in the current technology. Summary of the Invention
[0004] The technical problem this application aims to solve is that current PaaS platforms require the development of identical module code for each application to implement access control. When there are a large number of applications, this repetitive work represents a significant waste of resources in agile development and rapid delivery paradigms.
[0005] To address the aforementioned technical issues, this application provides a multi-tenant cloud platform management system based on a PaaS platform, comprising: a cloud platform management system for recording and configuring various service information of the system, and configuring relevant service businesses for users requesting leasing based on the current network status, user status, and system-issued restriction parameters; application clients connected to the cloud platform management system, which send request configuration information to the cloud platform management system through their default proxy server, and are used to connect to and deploy various corresponding services for users; and a tenant management system for receiving and forwarding management and configuration information of the application clients from the cloud platform management system; wherein the cloud platform management system and the application clients are connected through the tenant management system; wherein the tenant management system includes multiple independent tenants, and each independent tenant connects to multiple application clients.
[0006] According to embodiments of this application, the cloud platform management system further includes application terminals, which include mobile phones, desktop computers, POS terminals, and laptops.
[0007] According to an embodiment of this application, the tenant management system includes a database module, which comprises a tenant information table, a tenant-brand relationship table, a brand store-management company association table, and other application data tables. The tenant information table stores tenant-entered information, including at least tenant account information, tenant administrator accounts, contracted company administrator accounts, store administrator accounts, and transaction data for all services under the tenant; online count, latest update time, validity status, and other control proxy server attributes. The tenant-brand relationship and brand store-management company association tables record the corresponding role permissions assigned to the relevant accounts of the tenant, including creating general finance, regional finance, operations roles, and store roles. The other application data tables store web page third-party application data.
[0008] According to an embodiment of this application, the tenant management system includes a basic service back-end management system and a service back-end management system. The basic service back-end management system is used by merchants to view the services and applications provided by the cloud management platform. Through this system, they can access different service back-end management systems. Each service shares the same set of merchant user systems, but can be configured with roles and permissions for users individually. The service back-end management system is used for the standard back-end management system corresponding to the service. A service back-end management system determines the menus and data that a tenant can see based on the version and the organizational structure of the tenant entering the system.
[0009] According to an embodiment of this application, the back-end management system has an independent login URL, which can be accessed directly by the merchant or bank back-end management system, or by entering the tenant's login password through the login URL.
[0010] According to embodiments of this application, the cloud platform management system further includes an interface module, which at least includes an interface module for controlling the tenant management system, an application client management and control interface module, and an interface module for controlling the tenant management system. The tenant management system interface module is used to configure a specified independent tenant system for a tenant through the front-end configuration page of the cloud platform management system, and to return the configuration status of the tenant management system to the cloud platform management system after configuration. The application client management and control interface module is used to manage and control the application client through the front-end configuration page of the cloud platform management system. The interface module for controlling the tenant management system is used by the cloud platform management system to manage and control the tenant management system and to obtain information about all tenants in real time.
[0011] According to an embodiment of this application, the connection method of the application client is as follows: the application client sends a request configuration message to the cloud platform management system through its own default control proxy server. The cloud platform management system configures the control server for the requesting application client based on the current network status, the status of all control servers, and the limitation parameters of the cloud platform management system.
[0012] According to an embodiment of this application, when a new tenant is being created, the following steps are performed: activating a tenant account; adding relevant information, including the tenant logo, tenant tag, and account password; review—if the review fails, the information needs to be recreated; review—if the review passes, a tenant administrator account, a contracted company administrator account, and a store administrator account need to be created; creating roles, including general finance, regional finance, operations, and store roles; and granting the relevant accounts the corresponding role permissions, including granting the company administrator account regional finance permissions.
[0013] According to an embodiment of this application, the service activation method for the application client corresponding to the tenant is to first select the version, then select the application type, and after the application client service is activated, preview it and apply it to the tenant.
[0014] According to an embodiment of this application, a tenant can activate services for multiple application clients. The services of the application clients uniformly use the coupons and cash cards in the tenant's card package service to make payments using the "one-click" payment mode.
[0015] Compared with the prior art, this application has the following beneficial effects:
[0016] 1. Convenient service activation: This solves the problem of application deployment for tenants. Compared with traditional application service deployment methods, which require independent database establishment, related business development and deployment, this advantage allows for very simple service activation (including application-level C-end and management backend) for different tenants.
[0017] 2. Adopting a microservices foundation: Business and technology can be horizontally scaled; each service can provide business services independently without affecting each other, reducing the risk of single points of failure.
[0018] 3. One-click payment solves the problem of card and coupon synchronization in a single-tenant, multi-application model, allowing for unified payment without affecting financial clearing and settlement.
[0019] 4. Multi-tenant Clearing and Settlement: Solves the transaction clearing and settlement problem for multiple tenants and multiple applications. Generates reconciliation statements based on the transaction and settlement methods of different applications. This includes generating clearing and settlement statistics reports for each tenant account according to the payment period of each merchant and the handling fee or commission ratio. It also connects to UnionPay online transfer to realize the interface for direct online transfer. Attached Figure Description
[0020] To more clearly illustrate the technical solutions of the embodiments of this application, the accompanying drawings of the embodiments will be briefly described below. Obviously, the drawings described below only relate to some embodiments of this application, and are not intended to limit this application.
[0021] Figure 1 An exemplary structure of the PAAS platform provided in this embodiment of the invention;
[0022] Figure 2 This is a flowchart of the tenant activation process in an embodiment of the present invention;
[0023] Figure 3 This is a flowchart illustrating the process of enabling services for tenants in an embodiment of the present invention.
[0024] Figure 4 This is a flowchart of the "one-click payment" model in an embodiment of the present invention. Detailed Implementation
[0025] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of this application. Based on the described embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.
[0026] Unless otherwise defined, the technical or scientific terms used herein shall have the ordinary meaning as understood by one of ordinary skill in the art to which this application pertains. The terms “first,” “second,” and similar terms used in the specification and claims of this patent application do not indicate any order, quantity, or importance, but are merely used to distinguish different components. Similarly, the terms “an” or “a,” and similar terms, do not indicate a limitation of quantity, but rather indicate the presence of at least one.
[0027] In multi-tenancy technology, a tenant refers to a customer using system or computer computing resources. However, in multi-tenancy technology, a tenant encompasses all data within the system that can be identified as a specific user, including account and statistical information, various data created by the user within the system, and the user's customized application environment. Tenants use application systems or computing resources developed or built by vendors. The application systems designed by vendors may accommodate multiple users in the same environment. To enable multiple user environments to run on the same application and computing environment, the application and computing environment must be specially designed. Besides allowing the system platform to allow multiple copies of the same application to run simultaneously, protecting the privacy and security of tenant data is also a key aspect of multi-tenancy technology.
[0028] Multi-tenancy technology enables multiple tenants to share system instances while also allowing for personalized customization of those instances. By using multi-tenancy, common system components are shared, while unique components are isolated. Resource reuse across multiple tenants simplifies resource management and maintenance, effectively reducing application development costs. Furthermore, sharing a single application instance among tenants allows all tenants to upgrade simultaneously when the application is upgraded. Additionally, because multiple tenants share the same core codebase, system upgrades only require upgrading the same core code.
[0029] The multi-tenant cloud management platform provides services to banks and merchants, packaged into a set of microservices, offering a standard back-end management system and a standard C-end application system. For example, the food delivery service includes a food delivery back-end, a WeChat mini-program, and an Alipay mini-program; the service has multiple versions, including an initial super version, a basic version, and an advanced version, and a customized version can be set.
[0030] Tenant Basic Service Back-end Management: Merchants can view the services and applications provided by the multi-tenant cloud management platform. Through this, they can access different service back-end management systems. Each service shares the same merchant user system, but users can be assigned roles and permissions individually.
[0031] Service Back-End Administrator: The standard back-end administrator corresponding to the service. The menus and data visible to users are determined by the version and the organizational structure of the accessing user. It has an independent login URL, accessible directly from the merchant or bank back-end administrator, or by entering the username and password via the login URL.
[0032] according to Figure 1 , Figure 2 , Figure 3 , Figure 4 This application presents a multi-tenant cloud platform management system based on a PaaS platform, comprising: a cloud platform management system for recording and configuring various service information of the system, and configuring relevant service businesses for users requesting leasing based on the current network status, user status, and system-issued restriction parameters; an application client connected to the cloud platform management system, which sends request configuration information to the cloud platform management system through its default proxy server, and is used to connect to and deploy various corresponding services for users; and a tenant management system for receiving and forwarding management and configuration information of the application client from the cloud platform management system; wherein the cloud platform management system and the application client are connected through the tenant management system; wherein the tenant management system includes multiple independent tenants, and each independent tenant connects to multiple application clients.
[0033] Furthermore, the cloud platform management system also includes application terminals, which include mobile phones, desktop computers, POS terminals, and laptops.
[0034] Furthermore, the tenant management system includes a database module, which comprises a tenant information table, a tenant-brand relationship table, a brand store-management company association table, and other application data tables. The tenant information table stores tenant-entered information, including at least tenant account information, tenant administrator accounts, contracted company administrator accounts, store administrator accounts, and transaction data for all services under the tenant; online count, latest update time, validity status, and other control proxy server attributes. The tenant-brand relationship and brand store-management company association tables record the corresponding role permissions assigned to the relevant accounts of the tenants, including the creation of general finance, regional finance, operations roles, and store roles. Other application data tables store web page and third-party application data.
[0035] Furthermore, the tenant management system includes basic service back-end management and service back-end management. The basic service back-end management is used by merchants to view the services and applications provided by the cloud management platform. Through this, they can access different service back-end management systems. Each service shares the same merchant user system, but roles and permissions can be configured and assigned to users individually. The service back-end management system is the standard back-end management system corresponding to each service. A service back-end management system determines the menus and data that a tenant can see based on the version and the organizational structure of the tenant accessing it. Furthermore, each service back-end management system has an independent login URL, which can be accessed directly from the merchant or bank back-end management system, or by entering the tenant's login password through the login URL.
[0036] Furthermore, the cloud platform management system also includes an interface module, which at least includes an interface module for controlling the tenant management system, an application client management and control interface module, and an interface module for controlling the tenant management system. The tenant management system interface module is used to configure a specified independent tenant system for a tenant through the front-end configuration page of the cloud platform management system, and to report the configuration status of the tenant management system to the cloud platform management system after configuration. The application client management and control interface module is used to manage and control the application client through the front-end configuration page of the cloud platform management system. The interface module for controlling the tenant management system is used by the cloud platform management system to manage and control the tenant management system and to obtain information about all tenants in real time.
[0037] It should be noted that the cloud platform management system may also include organization management, platform role management, platform tenant management, audit management, platform configuration, and push notifications. Specifically, the cloud platform management system, through the cooperation between various units, is mainly used to manage the platform's own tenants and roles, as well as the platform's own parameter configurations (such as connection timeout settings). Here, the organization refers to both the organization of the platform tenant and the organization of the cluster tenant. Audit management records all operations within the platform (including cluster and platform operations), including login, logout, parameter configuration, tenant management, role management, and group management operations, recording the operation time and tenant name.
[0038] Furthermore, the application client connects as follows: the application client sends a configuration request message to the cloud platform management system through its default control proxy server. The cloud platform management system configures the control server for the requesting application client based on the current network status, the status of all control servers, and the limiting parameters of the cloud platform management system.
[0039] Furthermore, when a new tenant is being created, the following steps are performed: Activate the tenant account; Add relevant information, including the tenant logo, tenant tag, account password; Review – If the review fails, the information needs to be recreated; Review – If the review passes, the tenant administrator account, contracted company administrator account, and store administrator account need to be created; Create roles, including general finance, regional finance, operations, and store roles; Assign the corresponding role permissions to the relevant accounts, including granting regional finance permissions to the company administrator account.
[0040] It's important to note that a tenant system contains multiple tenants, and each tenant can include multiple clusters, each containing various resources. When the cloud platform management system has multiple clusters, when allocating tenant resources, multiple clusters (which require the Ranger service to be installed) will be displayed as candidates in the resource list. If resources from multiple clusters are selected, then that tenant contains resources from multiple clusters. It's crucial to understand that this only indicates the tenant contains multiple cluster resources, not that the tenant manages multiple clusters. A tenant contains multiple cluster resources, and a tenant administrator manages the tenant, meaning the tenant administrator can manage multiple clusters, but can only manage the clusters contained within a given tenant.
[0041] Furthermore, the service activation method for the application client corresponding to the tenant is to first select the version, then select the application type, and after the application client service is activated, preview it and apply it to the tenant.
[0042] Furthermore, a tenant can activate services for multiple application clients, and the services of these application clients can uniformly use the coupons and cash cards in the tenant's card package service for a "one-click" payment model.
[0043] The core operation of a specific embodiment of this application is as follows:
[0044] Step 1: Tenant Creation
[0045] One tenant account corresponds to multiple brands, one brand corresponds to multiple stores, and one store corresponds to multiple management / contracting companies.
[0046] The tenant activation process is as follows:
[0047] 1) Activate tenant accounts;
[0048] 2) Add relevant information (tenant logo, tenant tag, account password, etc.);
[0049] 3) Review – If the review fails, the information needs to be recreated.
[0050] 4) Review – Once the review is approved, you need to create a tenant administrator account, a contracted company administrator account, and a store administrator account;
[0051] 5) Create roles: General Finance, Regional Finance, Operations, and Store roles.
[0052] 6) Assign appropriate role permissions to relevant accounts. For example, after granting the company administrator account regional financial permissions, the branch administrator can only view relevant data under that company.
[0053] Step 2: Tenants activate the service
[0054] 1): Select the service type, such as "gift card" or "mall" service, select the tenant and version, and then activate it;
[0055] 2) After activation, select the corresponding management menu to access the services. The configuration will take effect and become visible in the services management section.
[0056] 3): Service activation method for C-end applications: Select the version and application type, such as "WeChat Mini Program", "Alipay Mini Program", "h5", etc. After activation, you can preview the effect and apply it to the tenant.
[0057] Step 3: Settlement and Clearing of Tenant Applications
[0058] The multi-tenant clearing and settlement system is based on the "one-stop" payment model, which can clearly calculate the data of each transaction. It can also determine the settlement amount according to the settlement cycle requirements of merchants, using different write-off calculation methods for directly operated companies and franchisees, thus providing technical support for merchants' reconciliation and clearing and settlement needs.
[0059] 1) When C-end users place an order and make payment in the online store, they can select the card wallet option.
[0060] 2) The business system calls the [Card Pack Service] to query the user's available cards and coupons;
[0061] 3) After the user selects an available coupon, such as a gift certificate or a cash card;
[0062] 4) Order submission, calculation of discount amount, and generation of pending payment order;
[0063] 5) Order payment request, which invokes the [Third-Party Payment Service] cashier;
[0064] 6) If the user successfully pays, a pending order will be generated;
[0065] 7) If the user cancels the payment, a pending payment order will be generated.
[0066] Step 4: Automated Reconciliation
[0067] The reconciliation work to be completed includes internal reconciliation and fund reconciliation. Fund reconciliation is further divided into reconciliation with payment channels and internal reconciliation. Internal reconciliation verifies the consistency between the accounts in the account system and the payment records. This process runs regularly in the background and generally does not produce errors. However, if errors do occur, manual processing is required. For channel reconciliation, banks and third-party payment providers typically provide T+1 reconciliation statements. The clearing and settlement reconciliation system retrieves the previous day's reconciliation statements from banks daily and verifies all transaction records. At the same time, based on the reconciliation statements obtained from the banks, the accounting for the collected funds is recorded.
[0068] The multi-tenant cloud platform management system based on multi-leasing technology aggregates transaction data of all services under a tenant and compares it with payment channel bills through the services opened by the tenant, reconciling accounts on a daily or monthly basis, and supports third-party systems to download report files through interfaces.
[0069] Step 5: Automated Profit Sharing
[0070] The settlement methods and settlement rates for tenant leasing services vary. The clearing system will automatically generate clearing statistical reports for each store and management company on a T+1 cycle, based on the tenant's profit-sharing method and handling fee or commission ratio.
[0071] Step Six: Settlement
[0072] Based on the settlement report data, the system automatically summarizes the data into a settlement report according to the settlement cycle at the management company level, and supports online payment transfer.
[0073] In summary, this application has the following beneficial effects:
[0074] 1. Convenient service activation: This solves the deployment problem for tenants to activate applications. Compared with traditional application service deployment methods, which require independent database establishment, related business development and deployment, this advantage allows for very simple service activation (including the application layer C-end and management backend) for different tenants.
[0075] 2. Adopting a microservices foundation: Business and technology can be horizontally scaled; each service can provide business services independently without affecting each other, reducing the risk of single points of failure.
[0076] 3. One-click payment solves the problem of card and coupon synchronization in a single-tenant, multi-application model, allowing for unified payment without affecting financial clearing and settlement.
[0077] 4. Multi-tenant Clearing and Settlement: Solves the transaction clearing and settlement problem for multiple tenants and multiple applications. Generates reconciliation statements based on the transaction and settlement methods of different applications. This includes generating clearing and settlement statistics reports for each tenant account according to the payment period of each merchant and the handling fee or commission ratio. It also connects to UnionPay online transfer to realize the interface for direct online transfer.
[0078] The above description is merely an exemplary embodiment of this application and is not intended to limit the scope of protection of this application. The scope of protection of this application is determined by the appended claims.
Claims
1. A multi-tenant cloud platform management system based on a PaaS platform, characterized in that, include: The cloud platform management system is used to record and configure various service information of the system, and configure relevant service businesses for users requesting rental based on the current network status, user status and the restriction parameters issued by the system. The application client connects to the cloud platform management system. The application client sends configuration requests to the cloud platform management system through its default proxy server. The application client is used to connect to and deploy various corresponding services for users. The tenant management system is used to receive and forward the management and configuration information of the cloud platform management system for the application client; The tenant management system includes a database module, which comprises a tenant information table, a tenant-brand relationship table, a brand store-management company association table, and other application data tables. The database module includes a tenant information table, a tenant-brand relationship table, a brand store-management company association table, and other application data tables: The tenant information table is used to store tenant-entered information, including at least tenant account information, tenant administrator account, contracted company administrator account, store administrator account, and transaction data for all services under the tenant; Online users, latest update time, validity status, and other proxy server attributes: The table showing the relationship between tenants and brands, and the association between brand stores and management companies, is used to record the corresponding role permissions assigned to the relevant accounts of the tenants, including creating general finance, regional finance, operations roles, and store roles. The other application data tables are used to store data from third-party web applications; The cloud platform management system further includes an interface module, which includes at least an interface module for controlling the tenant management system, an application client management and control interface module, and an interface module for controlling the tenant management system. The interface module of the tenant management system is used to configure a specified independent tenant system for a tenant through the front-end configuration page of the cloud platform management system, and after the configuration is completed, to return the configuration status of the tenant management system to the cloud platform management system. The application client management and control interface module is used to manage and control the application client through the front-end configuration page of the cloud platform management system. The interface module for controlling the tenant management system is used by the cloud platform management system to manage the tenant management system and obtain information about all tenants in real time. The cloud platform management system and the application client are connected through the tenant management system. The tenant management system includes multiple independent tenants, and each independent tenant is connected to multiple application clients.
2. The multi-tenant cloud platform management system according to claim 1, characterized in that, It also includes application terminals, which include mobile phones, desktop computers, POS terminals and laptops.
3. The multi-tenant cloud platform management system according to claim 1, characterized in that, The tenant management system includes basic tenant service management and service management. The tenant basic service back-end management merchants are used to view the services and applications provided by the cloud management platform; through this, they can access different service back-end management, each service uses the same set of merchant user systems, but roles and permissions can be configured and assigned to users individually; The service back-end is used to serve the corresponding standard back-end. A service back-end determines the menus and data that a tenant can see based on the version and the organizational structure of the tenant entering the service.
4. The multi-tenant cloud platform management system according to claim 3, characterized in that, The service back-end management system has an independent login URL, which can be accessed directly from the merchant or bank back-end management system, or by entering the tenant's login password through the login URL.
5. The multi-tenant cloud platform management system according to claim 1, characterized in that, The application client connects in the following way: the application client sends a configuration request message to the cloud platform management system through its default control proxy server. The cloud platform management system configures the control server for the requesting application client based on the current network status, the status of all control servers, and the restriction parameters of the cloud platform management system.
6. The multi-tenant cloud platform management system according to claim 1, characterized in that, When a new tenant is being created, perform the following steps: Activate tenant accounts; Add relevant information, including tenant logo, tenant tag, account and password; Review – If the review fails, the information needs to be recreated. Review – Once the review is approved, you need to create tenant administrator accounts, contracting company administrator accounts, and store administrator accounts. Create roles, including general finance, regional finance, operations, and store roles; Assign appropriate role permissions to relevant accounts, including granting regional financial permissions to company administrator accounts.
7. The multi-tenant cloud platform management system according to claim 1, characterized in that, The service activation method for the application client corresponding to the tenant is to first select the version, then select the application type, and after the service of the application client is activated, preview it and apply it to the tenant.
8. The multi-tenant cloud platform management system according to claim 7, characterized in that, A tenant can activate services for multiple application clients, and the services of these application clients will uniformly use the coupons and cash cards in the tenant's card package service to make payments using the "one-click payment" mode.