Data processing system and method for data security enhancement

The system enhances data security in multitenant SaaS environments by encoding each tenant's data structure uniquely, ensuring confidentiality and flexibility, addressing the inefficiencies of existing methods.

WO2026009047A1PCT designated stage Publication Date: 2026-01-08INTERNATIONAL BUSINESS MACHINE CORPORATION
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
PCT/IB2025/053228
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-07-02
Filing Date
2025-03-27
Publication Date
2026-01-08

AI Technical Summary

Technical Problem

Existing methods for securing time-series IoT data in multitenant SaaS deployments are resource-intensive, costly, and inflexible, failing to provide effective data isolation and privacy in dynamic environments.

Method used

A data processing system that generates a unique encoding scheme for each tenant's data structure, using a hierarchical node identifier structure, to encode and store data in a way that makes it indecipherable to other tenants, enhancing security and flexibility.

Benefits of technology

The system ensures data confidentiality and integrity by preventing unauthorized access, while accommodating dynamic IoT data streams, and is cost-effective compared to conventional methods.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure IB2025053228_08012026_PF_FP_ABST
    Figure IB2025053228_08012026_PF_FP_ABST
Patent Text Reader

Abstract

A data processing system for data security enhancement, the data processing system includes a processor configured to identify a plurality of tenants in a multitenant software-as-a-service (SaaS) environment, where the data processing system is configured to operate in the multitenant SaaS environment. The processor is configured to generate a unique encoding scheme for each tenant identified in the multitenant SaaS environment and encode each tenant's data structure using the generated unique encoding scheme. The processor is configured to store each tenants' data in form of the encoded data structure in a database where encoded data structure of a first tenant of the plurality of tenants is indecipherable to a second tenant of the plurality of tenants and encoded data structure of the second tenant is indecipherable to the first tenant. The data processing system efficiently enhances the data security of each tenant's data in the multitenant SaaS environment.
Need to check novelty before this filing date? Find Prior Art

Description

DATA PROCESSING SYSTEM AND METHOD FOR DATA SECURITYENHANCEMENTFIELD OF TECHNOLOGY

[0001] The present disclosure relates generally to the field of data security and privacy and, more specifically, to a data processing system and a method for data security enhancement in a multitenant software-as-a-service (SaaS) environment.BACKGROUND

[0002] With the wide spread use of smart Intemet-of-Things (loT) sensors capable of capturing and storing time-series data, the security and protection of such data has become a major issue. This is particularly true in multitenant SaaS deployments that cater to multiple customers (or clients or tenants), where ensuring the privacy and isolation of each customer's data is paramount. In the multitenant SaaS deployments, multiple customers use the same deployment which means that a single instance or installation of a software application (e.g., a single application deployment (Business layer) or a database over a shared infrastructure) is shared between multiple tenants or customers leveraging the multitenant architecture for cost effectiveness and scalability. However, in such deployments, in an unlikely event of getting access to a customer’s time-series loT data, another customer may get an opportunity to misuse the accessed data. The existing approaches address this issue either by storing each customer's data in a separate database instance or by deploying customer-specific application and database layers. However, the aforementioned solutions are resource intensive and costly to implement and maintain, particularly in large-scale deployments with numerous customers.

[0003] Another approach involves following standard cybersecurity practices and certifications, such as ISO-27001 and SOC2, which outline general guidelines for data protection and access control. These practices have some significance, still they may not provide a specific solution to the unique challenges of securing timeseries loT data in a multitenant environment. Furthermore, the conventionaldatabase structures typically map each column to a specific property of the entity being stored, for example, name of the entity is stored in a column designated as “Name” or address of the entity is stored in another column designated as “Address” and the like. Such mapping is more prone to error and misuse and require significant modifications whenever customer-specific changes are required. This approach can be inflexible and may not readily accommodate the dynamic nature of loT data streams. Thus, there exists a technical problem of how efficiently the security of the time-series loT data can be enhanced in the multitenant SaaS deployments, while also enabling dynamic onboarding and storage of loT data.

[0004] Therefore, in the light of the foregoing discussion, there exists a need to overcome the aforementioned drawbacks associated with the conventional methods of securing loT data in the multitenant SaaS deployments.BRIEF SUMMARY OF THE DISCLOSURE

[0005] The present disclosure provides a data processing system and a method for data security enhancement in a multitenant software-as-a-service (SaaS) environment. The present disclosure seeks to provide a solution to the existing problem of how efficiently the security of time-series loT data can be enhanced in the multitenant SaaS environment, while also enabling dynamic onboarding and storage of loT data. An aim of the present disclosure is to provide a solution that overcomes at least partially the problems encountered in the prior art and provide an improved data processing system to ensure that data structure of each tenant in a multitenant SaaS environment is indecipherable to other tenants. Additionally, the present disclosure provides an improved method to enhance the data security in the multitenant SaaS deployment.

[0006] In one aspect, the present disclosure provides a data processing system for data security enhancement, the data processing system comprises: a processor configured to:identify a plurality of tenants in a multitenant software-as-a-service (SaaS) environment, where the data processing system is configured to operate in the multitenant SaaS environment; generate a unique encoding scheme for each tenant of the plurality of tenants identified in the multitenant SaaS environment; encode each tenant’s data structure using the generated unique encoding scheme; and store data associated with each tenant in form of the encoded data structure in a database; where encoded data structure of a first tenant of the plurality of tenants is indecipherable to a second tenant of the plurality of tenants and encoded data structure of the second tenant is indecipherable to the first tenant.

[0007] The disclosed data processing system efficiently enhances the data security of the time-series loT data of each tenant in the multitenant SaaS environment. The data processing system is configured to generate the unique encoding scheme for each tenant in the multitenant SaaS environment and encode each tenant’s data structure using the unique encoding scheme. The use of the unique encoding scheme for encoding data structure of each tenant enhances the data security by making the encoded data structure of the first tenant indecipherable to the second tenant and vice-versa. The unique encoding scheme includes using the hierarchical node identifier structure for encoding data structure of each tenant. The data associated with each tenant is stored in form of the encoded data structure in the database using the hierarchical node identifier structure. Consequently, an additional layer of security is added to each tenant’s data against unauthorized access and data breaches. The use of the unique encoding scheme for each tenant ensures that each tenant's data remains confidential and protected from unauthorized access. Furthermore, the data processing system manifests flexibility to readily accommodate the dynamic nature of loT data streams associated with each tenant.

[0008] In another aspect, the present disclosure provides a method for data security enhancement, the method comprising: identifying, by a processor, a plurality of tenants in a multitenant software-as-a- service (SaaS) environment; generating, by the processor, a unique encoding scheme for each tenant of the plurality of tenants identified in the multitenant SaaS environment; encoding, by the processor, each tenant’s data structure using the generated unique encoding scheme; and storing, by the processor, data associated with each tenant in form of the encoded data structure in a database, where encoded data structure of a first tenant of the plurality of tenants is indecipherable to a second tenant of the plurality of tenants and encoded data structure of the second tenant is indecipherable to the first tenant.

[0009] The method achieves all the advantages and technical effects of the data processing system of the present disclosure.

[0010] It has to be noted that all devices, elements, circuitry, units and means described in the present application could be implemented in the software or hardware elements or any kind of combination thereof. All steps which are performed by the various entities described in the present application as well as the functionalities described to be performed by the various entities are intended to mean that the respective entity is adapted to or configured to perform the respective steps and functionalities. Even if, in the following description of specific embodiments, a specific functionality or step to be performed by external entities is not reflected in the description of a specific detailed element of that entity which performs that specific step or functionality, it should be clear for a skilled person that these methods and functionalities can be implemented in respective software or hardware elements, or any kind of combination thereof. It will be appreciated that features of the present disclosure are susceptible to being combined in variouscombinations without departing from the scope of the present disclosure as defined by the appended claims.

[0011] Additional aspects, advantages, features, and objects of the present disclosure would be made apparent from the drawings and the detailed description of the illustrative implementations construed in conjunction with the appended claims that follow.BRIEF DESCRIPTION OF THE DRAWINGS

[0012] The summary above, as well as the following detailed description of illustrative embodiments, is better understood when read in conjunction with the appended drawings. For the purpose of illustrating the present disclosure, exemplary constructions of the disclosure are shown in the drawings. However, the present disclosure is not limited to specific methods and instrumentalities disclosed herein. Moreover, those skilled in the art will understand that the drawings are not too scaled. Wherever possible, like elements have been indicated by identical numbers.

[0013] Embodiments of the present disclosure will now be described, by way of example only, with reference to the following diagrams wherein:FIG. 1 is a block diagram illustrating a data processing system for data security enhancement, in accordance with an embodiment of the present disclosure;FIG. 2 is a flowchart of a method for data security enhancement, in accordance with an embodiment of the present disclosure;FIG. 3 illustrates an exemplary implementation scenario of utilizing a unique encoding scheme for each tenant’s data structure in a multitenant Software-as-a-Service (SaaS) environment, in accordance with an embodiment of the present disclosure; andFIG. 4 illustrates another exemplary implementation scenario of utilizing a unique encoding scheme for encoding of each solar plant’s data structureowned by a respective tenant in a multitenant SaaS environment, in accordance with an embodiment of the present disclosure.

[0014] In the accompanying drawings, an underlined number is employed to represent an item over which the underlined number is positioned or an item to which the underlined number is adjacent. A non-underlined number relates to an item identified by a line linking the non-underlined number to the item. When a number is non-underlined and accompanied by an associated arrow, the nonunderlined number is used to identify a general item at which the arrow is pointing.DETAILED DESCRIPTION OF THE DISCLOSURE

[0015] The following detailed description illustrates embodiments of the present disclosure and ways in which they can be implemented. Although some modes of carrying out the present disclosure have been disclosed, those skilled in the art would recognize that other embodiments for carrying out or practicing the present disclosure are also possible.

[0016] FIG. 1 is a block diagram illustrating a data processing system for data security enhancement, in accordance with an embodiment of the present disclosure. With reference to FIG. 1, there is shown a data processing system 100 configured to operate in a multitenant software-as-a-service (SaaS) environment 102 comprising a plurality of tenants 104. The data processing system 100 comprises a server 106, a database 108, and a user interface 110 connected to each other via a communication network 112. The server 106 includes a processor 114, a memory 116 and a network interface 118. The processor 114 may be communicatively coupled with the memory 116 and the network interface 118.

[0017] There is provided the data processing system 100 that may refer to a computer-based system or infrastructure that is designed to enhance data security in the multitenant SaaS environment 102. Alternatively stated, the data processing system 100 is configured to operate in the multitenant SaaS environment 102 and identify the plurality of tenants 104. The data processing system 100 is configured to store data of each tenant in the database 108 in form of an encoded data structure,with the encoding differing for each tenant. The data processing system 100 adds an extra layer of security to the data associated with each tenant, as the encoding scheme is unique to each tenant as well as to each entity (e.g., a solar energy plant) that is owned by a respective tenant and the encoded data structure cannot be decoded by other tenants. In an exemplary scenario, a first tenant has the ownership of two solar energy plants, for example, a plant 1 and a plant 2 and a user 1 has access to data structure of the plant 1 and a user 2 has access to data structure of the plant 2. The first tenant requires that data structure of each solar energy plant is indecipherable to a second tenant as well as to users who do not have access to any of the two solar energy plants. To achieve this, the data processing system 100 is configured to generate two unique encoding schemes, one for each solar energy plant and encode data structure of each solar energy plant and store data in form of the encoded data structure of both solar energy plants in the database 108. The encoded data structures of the plant 1 and the plant 2 are indecipherable to the second tenant. Moreover, the encoded data structure of the plant 1 is indecipherable to the user 2 who does not have access to data structure of the plant 1 and the encoded data structure of the plant 2 is indecipherable to the user 1 who does not have access to data structure of the plant 2. In this way, the uniqueness of the encoding scheme is not only for each tenant but also for each solar energy plant that is owned by the same tenant (i.e., the first tenant). The exemplary implementation scenarios are described in detail, for example, in FIGs. 3 and 4. The data processing system 100 as well as various components of the data processing system 100 are described in more detail, in the following way.

[0018] The multitenant SaaS environment 102 refers to an architecture where a single instance of a software application or system serves multiple tenants or customers simultaneously. In the multitenant SaaS environment 102, the software application and its components, such as a database layer, a codebase layer, and the like, are designed to support the plurality of tenants 104, simultaneously. The software application is designed to partition its data and configuration settings based on the plurality of tenants 104 to ensure that each tenants’ data remains separate and secure from other tenants.

[0019] Each tenant of the plurality of tenants 104 may be either an individual person or an individual entity, for example, a solar energy plant that utilizes the multitenant SaaS environment 102 to access and store their data, while sharing the same infrastructure and resources (e.g., the database 108) with other tenants. This approach is commonly used in cloud-based SaaS applications, where a single application instance can be shared among multiple tenants.

[0020] The server 106 is configured to communicate with the database 108 via the communication network 112. In an implementation, the server 106 may be a master server or a master machine that is a part of a data center that controls an array of other cloud servers communicatively coupled to it for load balancing, running customized applications, and efficient data management. Examples of the server 106 may include, but are not limited to a cloud server, an application server, a data server, or an electronic data processing device.

[0021] The database 108 may be referred to as an organized collection of semistructured data that is stored and managed in a way that allows for efficient retrieval, manipulation, and management of the semi-structured data.

[0022] The user interface 110 refers to a graphical ortextual representation that allows each of the plurality of tenants to interact with the server 106 and the database 108, to access and view the encoded data structure of a respective tenant by providing input commands, receive feedback, and access various functionalities and features of the server 106 and the database 108.

[0023] The communication network 112 includes a medium (e.g., a communication channel) through which the server 106 (more specifically, the processor 114) is configured to connect with the database 108 and store each tenant’s encoded data structure in the database 108. The communication network 112 may be a wired or wireless communication network. Examples of the communication network 112 may include, but are not limited to, a local area network (LAN), a wireless personal area network (WPAN), a wireless local area network (WLAN), a wireless wide area network (WW AN), a cloud network, a long-term evolution (LTE) network, a metropolitan area network (MAN), and / or Internet.

[0024] The processor 114 refers to a computational element that is operable to respond to and processes instructions that drive the data processing system 100. The processor 114 may refer to one or more individual processors, processing devices, and various elements associated with a processing device that may be shared by other processing devices. Additionally, the one or more individual processors, processing devices, and elements are arranged in various architectures for responding to and processing the instructions that drive the data processing system 100. In some implementations, the processor 114 may be an independent unit and may be located outside the server 106 of the data processing system 100. Examples of the processor 114 may include but are not limited to, a hardware processor, a digital signal processor (DSP), a microprocessor, a microcontroller, a complex instruction set computing (CISC) processor, an application-specific integrated circuit (ASIC) processor, a reduced instruction set (RISC) processor, a very long instruction word (VLIW) processor, a state machine, a data processing unit, a graphics processing unit (GPU), and other processors or control circuitry.

[0025] The memory 116 refers to a volatile or persistent medium, such as an electrical circuit, magnetic disk, virtual memory, or optical disk, in which a computer can store data or software for any duration. Optionally, the memory 116 is a non-volatile mass storage, such as a physical storage media. Furthermore, a single memory may encompass and, in a scenario, and the data processing system 100 is distributed, the processor 114, the memory 116 and / or storage capability may be distributed as well. Examples of implementation of the memory 116 may include, but are not limited to, an Electrically Erasable Programmable Read-Only Memory (EEPROM), Dynamic Random-Access Memory (DRAM), Random Access Memory (RAM), Read-Only Memory (ROM), Hard Disk Drive (HDD), Flash memory, a Secure Digital (SD) card, Solid-State Drive (SSD), and / or CPU cache memory.

[0026] The network interface 118 refers to a communication interface to enable communication of the server 106 to any other external device, such as the database 108 and the user interface 110. Examples of the network interface 118 include, but are not limited to, a network interface card, an antenna, an antenna array, a transceiver, and the like.

[0027] In operation, the data processing system 100 comprises the processor 114 configured to identify the plurality of tenants 104 in the multitenant SaaS environment 102, where the data processing system 100 is configured to operate in the multitenant SaaS environment 102. The processor 114 of the data processing system 100 in the multitenant SaaS environment 102 is configured to identify the plurality of tenants 104, which share and utilize a common resource or service. Each of the plurality of tenants 104 is configured to utilize the database 108 to store the respective data in form of an encoded data structure.

[0028] The processor 114 is further configured to generate a unique encoding scheme for each tenant of the plurality of tenants 104 identified in the multitenant SaaS environment 102. The term ‘unique encoding scheme’ refers to a specific method or algorithm used to transform each tenant’s data structure into a distinct format, ensuring that each piece of information is represented by a unique code. The unique encoding scheme is generated specifically for each tenant, ensuring that the encoding of each tenant's data structure is different from other tenants. Moreover, the unique encoding scheme is generated for each solar energy plant of each tenant which further ensures that encoding of each solar energy plant’s data structure is different from other solar energy plants. In an implementation scenario, at the time of initial configuration of each solar energy plant, a mapping file known as COR file can be generated and used as the basis for encoding of each solar energy plant’s data structure. The COR file typically, used to represent complex data structures and objects in a standardized and platform independent format. The generation of the unique encoding scheme for each tenant as well as for each solar energy plant of each tenant prevents unauthorized access to data by ensuring that each tenant's data structure as well as each plant’s data structure is encoded using adistinct encoding scheme. Thus, the uniqueness of the encoding scheme is not limited to each tenant but also applicable to each solar energy plant of each tenant.

[0029] In some implementations, the processor 114 is further configured to dynamically generate the unique encoding scheme for each tenant’s data structure. The unique encoding scheme is implemented to ensure data separation and privacy for each tenant’s data. By generating distinct encoding schemes, the data processing system 100 prevents data from being mixed or accessed by unauthorized users. This approach enhances data security and confidentiality, providing tenants with a dedicated and isolated data environment. By virtue of dynamically generating the unique encoding scheme for each tenant’s data structure, an efficient data management and retrieval of data from the encoded data structure can be enabled. Thus, the data processing system 100 manifests an improved performance and responsiveness, and allows the plurality of tenants 104 to efficiently access and analyze their respective data without interference from other tenants' data.

[0030] The processor 114 is further configured to encode each tenant’s data structure using the generated unique encoding scheme. The data processing system 100 enhances data security by encoding each tenant’s data structure using the generated unique encoding scheme. By using the unique encoding scheme for encoding of each tenant’s data structure, the data processing system 100 ensures that the data of one tenant cannot be easily deciphered by another tenant. This adds an additional layer of protection to the sensitive data being stored in the database 108.

[0031] In some implementations, data associated with each tenant comprises time-series data which corresponds to sensor data captured by Internet of Things (loT) devices. The term ‘time-series data’ refers to a collection of data points or observations that are recorded, measured, or generated in a sequential manner over a specific period of time. In an exemplary implementation scenario of a solar energy plant, the time-series data may correspond to a number of signals generated by the loT devices, such as an inverter, String Monitoring Box (SMB), Weather Station (WS), Multi -function Meter (MFM), and the like. In an implementation scenario,the time-series data may correspond to data which is in transit (from a solar energy plant to the database 108) as well as to data which is at rest. Moreover, the timeseries data may correspond to semi-structured data.

[0032] In some implementations, generation of the unique encoding scheme comprises generation of a hierarchical node identifier structure for representing components of a system associated with the time-series data, where the hierarchical node identifier structure comprises identifiers for devices, parameters and alarms of the system. The term ‘hierarchical node identifier structure’ refers to a framework that organizes and represents nodes (or devices) in a hierarchical manner, where each node is assigned a unique identifier that reflects its position within the hierarchy, allowing for efficient and structured management and navigation of the nodes. To achieve this, the data processing system 100 utilizes a template master that defines distinguishable signals (or parameters) for each device type, such as inverters, SMBs, WS, and MFM. Each device has its own set of signals that is required to be captured. The hierarchical node identifier structure is generated by assigning identifiers to devices, parameters, and alarms associated with the system, such as a solar energy plant system. The hierarchical node identifier structure may be generated by combining a server ID, network ID, device ID, and parameter ID. For example, the hierarchical node identifier structure may be represented as RRR SSS NNNN DDD PPPP AA where, initial 3 bits are Reserved (R), 3 bits for server (S) ID, 4 bits for network (N) ID, 3 bits for device (D) ID, 4 bits for parameter (P) ID and 2 bits for alarms (A). For example, in case of an inverter with an Active power tag then, the node ID would be derived using a specific logic. If the server ID is 2, the network ID is 3, the device ID is 4, and the parameter ID is 10 then, the device ID is computed as 002 0003 004 0000 00 and the parameter ID (i.e., the active power node ID) is computed as 002 0003 004 0010 00. When the encoded data structure is stored in the database 108 (e.g., Influx database), a measurement with the device having an encoding ID 002 0003 004 0000 00 and the active power encoded field ID 002 0003 004 0010 00 is created. The inverter may have other parameters, such as AC breaker counter, AC circuit breaker status, and the like.Each parameter is mapped to a corresponding parameter ID. Similarly, each device type has several parameters mapped to their respective parameter IDs.

[0033] Furthermore, in case if portfolio-wise active powers are required then, a specific formula utilizing the device ID, and the parameter ID is used to create a list of columns for the data search query. The formula is device ID + (the parameter ID x 100). For example, the device ID is 002 0003 004 0000 00 and the parameter ID is 10 then, the list of columns generated for data search query are:002 0003 004 0000 00 + (10x100) = 002 0003 004 0010 00002 0003 005 0000 00 + (10x100) = 002 0003 005 0010 00002 0003 006 0000 00 + (10x100) = 002 0003 006 0010 00

[0034] When a tenant interacts with the solar energy plant through the user interface 110, the tenant is capable of viewing the solar energy plant hierarchy using names and IDs. When selecting a parameter, the data processing system 100 maps the parameter to a corresponding parameter ID, multiplies it by 100, and generates the list of columns for the data search query. This process allows for the creation of a unique encoding scheme tailored to each tenant's specific data structure. By generating the hierarchical node identifier structure, the data processing system 100 can accurately represent the components of the system (i.e., the solar energy plant system) associated with the time-series data. This allows for efficient data retrieval and analysis, as well as seamless navigation of the solar plant hierarchy using names and IDs. By representing the components of the system (i.e., the solar energy plant system) with unique identifiers, the data processing system 100 can easily map parameters selected by the tenant to their corresponding parameter IDs. This mapping is done by multiplying the mapped parameter ID by 100, which generates a list of columns for the data search query. This ensures that the data processing system 100 can quickly retrieve the relevant data from the encoded data structure for the selected parameters, providing tenants with accurate and timely information about the solar energy plant.

[0035] The processor 114 is further configured to store data associated with each tenant in form of the encoded data structure in the database 108 where encoded data structure of a first tenant of the plurality of tenants 104 is indecipherable to a second tenant of the plurality of tenants 104 and encoded data structure of the second tenant is indecipherable to the first tenant. The data of each tenant is stored in form of the encoded data structure in the database 108 (i.e., the Influx Database). By virtue of storing the data in form of the encoded data structure in the database 108, an enhanced level of protection against unauthorized access and data breaches is obtained. The unique encoding scheme used for encoding each tenant's data structure adds complexity and makes it more challenging for potential attackers to interpret and misuse the data. This further safeguard the confidentiality and integrity of the stored information of each tenant, ensuring the data security enhancement. Furthermore, by making the encoded data structure indecipherable between tenants (such as the first tenant and the second tenant) of the plurality of tenants 104, the data processing system 100 prevents unauthorized access and protects the confidentiality of each tenant's data.

[0036] In some implementations, the processor 114 is further configured to store data associated with each tenant in form of the encoded data structure in the database 108 using the hierarchical node identifier structure. The hierarchical node identifier structure is designed in a way to accommodate the unique encoding scheme for each tenant’s data structure. The encoding of data structure differs for each tenant, and it is required to store and retrieve the data from the encoded data structure accurately and efficiently. Moreover, the use of the hierarchical node identifier structure for storing each tenants’ data in form of the encoded data structure enables efficient storage and retrieval of data from the encoded data structure whenever requested by a respective tenant. Additionally, the hierarchical node identifier structure allows for flexibility in accommodating client-specific changes to the stored data.

[0037] In some implementations, the data processing system 100 further comprises the user interface 110 configured to enable each tenant of the pluralityof tenants 104 to access and view the encoded data structure associated with the respective tenant. The user interface 110 allows each tenant to access and view the respective encoded data structure by utilizing the hierarchical node identifier structure, which is represented by device IDs and parameter IDs. By encoding the data structure and providing each tenant with a unique access method, the data processing system 100 ensures that only authorized tenants can view their specific data. This enhances data privacy and protects sensitive information.

[0038] In some implementations, the processor 114 is further configured to provide each tenant with a capability to decode the encoded data structure associated with the respective tenant. The capability to decode the encoded data structure associated with each tenant provides each of the plurality of tenants 104 with a seamless experience. Each of the plurality of tenants 104 can easily navigate their respective data using the server IDs, network IDs, device IDs, parameter IDs, and the like, and retrieve the desired data without any hassle. The decoding capability also enables efficient data search queries, as the data processing system 100 can quickly identify the relevant data based on the network IDs, device IDs, parameter IDs, and the like, from the database 108. The decoding capability enhances the usability, security, and efficiency of the data processing system 100.

[0039] In some implementations, the processor 114 is further configured to generate a unique encoding scheme for data encoding of each tenant of the plurality of tenants 104 identified in the multitenant SaaS environment 102. In addition to encoding of each tenant’s data structure, the data processing system 100 may be configured to encode each tenant’s data. By encoding both the data structure and the individual tenant data, the data processing system 100 provides a comprehensive protection and management of sensitive information and offers a robust solution for data security and privacy in complex and shared environments. By generating the unique encoding scheme for encoding of each tenant’s data, the data processing system 100 ensures that even if a tenant gains access to encoded data of another tenant, the tenant would not be able to understand or manipulate the accessed data without knowledge of the specific encoding scheme. This enhancesthe overall security of the data associated with each tenant and safeguards the confidentiality of each tenants' information.

[0040] In some implementations, the processor 114 is further configured to monitor access to the encoded data structure and generate alarms in case of unauthorized access attempts. The data stored in form of the encoded data structure to the database 108 is monitored for any unauthorized access attempts. The monitoring of access to the data stored in form of the encoded data structure in the database 108, adds an extra layer of security to the stored data. By detecting and generating alarms in case of unauthorized access attempts, the data processing system 100 ensures the protection of sensitive data and prevents unauthorized tenants from gaining access to the stored data.

[0041] Thus, the data processing system 100 efficiently enhances the security of each tenant’s data in the multitenant SaaS environment 102. The processor 114 of the data processing system 100 is configured to generate the unique encoding scheme for each tenant’s data structure in the multitenant SaaS environment 102 and encode each tenant’s data structure using the unique encoding scheme. The use of the unique encoding scheme for encoding of each tenant’s data structure enhances the data security by making the data structure of the first tenant indecipherable to the second tenant and vice-versa. The data of each tenant is stored in form of the encoded data structure in the database 108 using the hierarchical node identifier structure. Consequently, an additional layer of security is added to each tenant’s data against unauthorized access and data breaches. The use of the unique encoding scheme for each tenant ensures that each tenant's data remains confidential and protected from unauthorized access. Furthermore, the data processing system 100 manifests flexibility to readily accommodate the dynamic nature of loT data streams associated with each tenant’s data.

[0042] Moreover, the use of the data processing system 100 in the multitenantSaaS environment 102 manifests a cost-effective solution in addition to the data security enhancement in comparison to the conventional multitenant SaaS deployments. In the conventional multitenant SaaS deployments, either eachtenant’s data is stored in a separate database instance or the customer-specific application and database layers are deployed. Such multitenant SaaS deployments are resource intensive and costly to implement and maintain, particularly in large- scale deployments with numerous customers. In comparison to the conventional multitenant SaaS deployments, the data processing system 100 enables an efficient storage of each tenant’s data in the same database (i.e., the database 108) by virtue of using the unique encoding scheme for each tenant’s data structure. The use of the unique encoding scheme (i.e., the hierarchical node identifier structure) for encoding of each tenant’s data structure not only enhances the data security but also, enables an efficient storage of data in form of the encoded data structure in the database 108 and an accurate and quick retrieval of data from the stored encoded data structure from the database 108 whenever the data is requested by any of the plurality of tenants 104. In this way, the use of the data processing system 100 in the multitenant SaaS environment 102 manifests cost-effectiveness in addition to the data security enhancement of each tenant’s data even in large-scale deployments with numerous customers.

[0043] FIG. 2 is a flowchart of a method for data security enhancement, in accordance with an embodiment of the present disclosure. FIG. 2 is described in conjunction with the elements of FIG. 1. With reference to FIG. 2, there is shown a method 200 for data security enhancement. The method 200 includes steps 202 to 208. The processor 114 of the server 106 is configured to execute the method 200.

[0044] At step 202, the method 200 comprises identifying, by the processor 114, the plurality of tenants 104 in the multitenant software -as -a-service (SaaS) environment 102. The method 200 is implemented in the multitenant SaaS environment 102 to identify the plurality of tenants 104 where each tenant either corresponds to an individual person or an individual entity, for example, a solar energy plant that utilizes the multitenant SaaS environment 102 to access and store their data, while sharing the same infrastructure and resources (i.e., the database 108) with other tenants.

[0045] At step 204, the method 200 further comprises generating, by the processor 114, a unique encoding scheme for each tenant of the plurality of tenants 104 identified in the multitenant SaaS environment 102. The generation of the unique encoding scheme for each tenant ensures the security of each tenant’s data by preventing unauthorized access and data breaches.

[0046] In some implementations, the method 200 further comprises dynamically generating, by the processor 114, the unique encoding scheme for each tenant’s data structure. The dynamic generation of the unique encoding scheme for each tenant’s data structure maintains the uniqueness of the encoding scheme which, ensures the data protection and privacy of each tenant’s data.

[0047] At step 206, the method 200 further comprises encoding, by the processor 114, each tenants’ data structure using the generated unique encoding scheme. The encoding of each tenant’s data structure using the unique encoding scheme enhances the security of each tenant’s data and makes it difficult for unauthorized users to access or decipher the encoded data structure.

[0048] In some implementations, where data associated with each tenant comprises time-series data which corresponds to sensor data captured by Internet of Things (loT) devices. The time-series data has been described in detail, for example, in FIG. 1. In an exemplary implementation scenario of a solar plant, the time-series data may correspond to a number of signals generated by the loT devices, such as an inverter, SMB, WS, MFM, and the like.

[0049] In some implementations, generation of the unique encoding scheme comprises generation of a hierarchical node identifier structure for representing components of a system associated with the time-series data, where the hierarchical node identifier structure comprises identifiers for devices, parameters and alarms of the system. The hierarchical node identifier structure has been described in detail, for example, in FIG. 1. The hierarchical node identifier structure comprises identifiers to devices, parameters, and alarms associated with the system, such as a solar power plant system. By generating the hierarchical node identifier structure, the method 200 can be used to accurately represent various components of thesystem (i.e., the solar power plant system) associated with the time-series data. This allows for efficient data retrieval and analysis, as well as seamless navigation of the solar plant hierarchy using device IDs and parameter IDs.

[0050] At step 208, the method 200 further comprises storing, by the processor 114, data associated with each tenant in form of the encoded data structure in the database 108, where encoded data structure of a first tenant of the plurality of tenants 104 is indecipherable to a second tenant of the plurality of tenants 104 and encoded data structure of the second tenant is indecipherable to the first tenant. The storage of each tenant’s data in form of the encoded data structure in the database 108 brings an additional level of protection against unauthorized access and data breaches.

[0051] In some implementations, the method 200 further comprises storing, by the processor 114, data associated with each tenant in form of the encoded data structure in the database 108 using the hierarchical node identifier structure. The storage of each tenant’s data in form of the encoded data structure in the database 108 using the hierarchical node identifier structure enables an efficient storage and retrieval of data from the encoded data structure whenever requested by a respective tenant.

[0052] In some implementations, the method 200 further comprises providing, by the processor 114, each tenant with a capability to decode the encoded data structure associated with the respective tenant. The capability to decode the encoded data structure associated with each tenant provides each of the plurality of tenants 104 an easy navigation of the respective data and efficient data search queries.

[0053] In some implementations, the method 200 further comprises generating, by the processor 114, a unique encoding scheme for data encoding of each tenant of the plurality of tenants 104 identified in the multitenant SaaS environment 102. By generating the unique encoding scheme for each tenant’s data in addition to the encoding scheme for each tenant’s data structure, the method 200 makes the dataas well as the data structure of each tenant indecipherable among the plurality of tenants 104.

[0054] In some implementations, the method 200 further comprises, monitoring, by the processor 114, access to the encoded data structure and generate alarms in case of unauthorized access attempts. By detecting and generating alarms in case of unauthorized access attempts, the method 200 ensures the protection of sensitive data and prevents unauthorized tenants from gaining access to the data stored in form of the encoded data structure.

[0055] The steps 202 to 208 are only illustrative, and other alternatives can also be provided where one or more steps are added, or one or more steps are provided in a different sequence without departing from the scope of the claims herein.

[0056] There is provided a computer program comprising instructions for carrying out all the steps of the method 200. The computer program is executed on a computer system. The computer program is implemented as an algorithm, embedded in a software stored in the non-transitory computer-readable storage medium having program instructions stored thereon, the program instructions being executable by the one or more processors in the computer system to execute the method 200. The non-transitory computer-readable storage means may include, but are not limited to, an electronic storage device, a magnetic storage device, an optical storage device, an electromagnetic storage device, a semiconductor storage device, or any suitable combination of the foregoing. Examples of implementation of computer-readable storage medium, but are not limited to, an Electrically Erasable Programmable Read-Only Memory (EEPROM), a Random Access Memory (RAM), a Read Only Memory (ROM), a Hard Disk Drive (HDD), a Flash memory, a Secure Digital (SD) card, a Solid-State Drive (SSD), a computer-readable storage medium, and / or a CPU cache memory.

[0057] FIG. 3 illustrates an exemplary implementation scenario of utilizing a unique encoding scheme for encoding of each tenant’s data structure in a multitenant SaaS environment, in accordance with an embodiment of the present disclosure. FIG. 3 is described in conjunction with elements from FIGs. 1 and 2.With reference to FIG. 3, there is shown an exemplary implementation scenario 300 of utilizing a unique encoding scheme for each tenant’s data structure in the multitenant SaaS environment 102 comprising the plurality of tenants 104. The plurality of tenants 104 includes a first tenant 302 A, a second tenant 302B up to a Nth tenant 302N. Furthermore, the data structure of each of the plurality of tenants 104 is encoded using the unique encoding scheme, such as data structure of the first tenant 302A is encoded using a first encoding scheme 304A, and data structure of the second tenant 302B is encoded using a second encoding scheme 304B. Similarly, data structure of the Nth tenant 302N is encoded using a Nth encoding scheme 304N. Thereafter, the data of each of the plurality of tenants 104 is stored in form of the encoded data structures in the database 108 using the communication network 112 (as shown in FIG. 1). The encoded data structure of the first tenant 302A is indecipherable to the second tenant 302B and to the Nth tenant 302N. Similarly, the encoded data structure of the second tenant 302B is indecipherable to the first tenant 302A and to the Nth tenant 302N.

[0058] In the multitenant SaaS environment 102, data structure of each of the plurality of tenants 104 is encoded using the unique encoding scheme comprising the hierarchical node identifier structure, which prevents unauthorized access to each tenant’s encoded data structure and ensures the data confidentiality and integrity. The data of each tenant is stored in form of the encoded data structures in the database 108 using the hierarchical node identifier structure which adds an enhanced level of security to each tenant’s data and enables an efficient management and retrieval of data from the encoded data structure. The hierarchical node identifier structure has been described in detail, for example, in FIG. 1. However, in conventional multitenant SaaS deployments, no encoding scheme is implemented therefore, data of each tenant is prone to unauthorized access and misuse. In contrast to, the multitenant SaaS environment 102 employing the unique encoding scheme for each tenant’s data structure eliminates the problem of unauthorized access and misuse of each tenant’s data.

[0059] FIG. 4 illustrates another exemplary implementation scenario of utilizing a unique encoding scheme for encoding of each solar plant’s data structure owned by a respective tenant in a multitenant SaaS environment, in accordance with an embodiment of the present disclosure. FIG. 4 is described in conjunction with elements from FIGs. 1, 2 and 3. With reference to FIG. 4, there is shown an exemplary implementation scenario 400 of utilizing a unique encoding scheme for each solar plant’s data structure owned by a respective tenant in the multitenant SaaS environment 102 comprising the plurality of tenants 104. In the exemplary implementation scenario 400, the plurality of tenants 104 includes the first tenant 302A and the second tenant 302B. Furthermore, the first tenant 302A has the ownership of two solar energy plants, for example, a first solar energy plant 402A and a second solar energy plant 402B. The second tenant 302B has the ownership of a third solar energy plant 404. The data structure of the first solar energy plant 402A is encoded using a first encoding scheme 406A. Similarly, the data structure of the second solar energy plant 402B is encoded using a second encoding scheme 406B. Thus, the uniqueness of the encoding scheme is not limited to the tenant but also applicable to each solar energy plant of each tenant. The data structure of the third solar energy plant 404 is encoded using a third encoding scheme 408. Thus, the data of each solar energy plant is stored in form of the encoded data structures into the database 108. There is further shown a first user 410, a second user 412 and a third user 414 who are accessing the database 108. The first user 410 has access to the encoded data structures of the first solar energy plant 402A and the second solar energy plant 402B (represented by a set of dotted lines 416), which are owned by the first tenant 302A. The second user 412 has access only to the encoded data structure of the second solar energy plant 402B (represented by a set of dotted lines 418), despite of being owned by the same tenant that is the first tenant 302A. The third user 414 has access exclusively to the encoded data structure of the third solar energy plant 404 (represented by a set of dotted lines 420), which is owned by the second tenant 302B. By virtue of using the unique encoding scheme for encoding of each solar plant’s data structure, the second user 412 cannot access the first solar energy plant 402A data, even though the second user 412 has access to the secondsolar energy plant 402B data owned by the same tenant that is the first tenant 302A. Moreover, the third user 414 is completely restricted from accessing data of any of the first solar energy plant 402A and the second solar energy plant 402B, which belong to a different tenant. Thus, the user to plant relationship, combined with the unique encoding schemes, creates a robust data security model. Moreover, the user access is granular and can be controlled at the individual plant level, not just at the tenant level. The users cannot leverage access to one plant to gain unauthorized access to another plant’s data, even within the same tenant’s portfolio. The crosstenant data access is prevented, maintaining strict data isolation between different tenants’ solar energy plants. The data of each solar energy plant is stored in form of the encoded data structures in the database 108, but the unique encoding ensures that each user can only meaningfully access and interpret the data for the specific plants they are authorized to view. This approach effectively protects data security and integrity in the multitenant SaaS environment 102, preventing unauthorized access while allowing flexible user-to-plant access configurations.

[0060] Modifications to embodiments of the present disclosure described in the foregoing are possible without departing from the scope of the present disclosure as defined by the accompanying claims. Expressions such as “including”, “comprising”, “incorporating”, “have”, “is” used to describe, and claim the present disclosure are intended to be construed in a non-exclusive manner, namely allowing for items, components or elements not explicitly described also to be present. Reference to the singular is also to be construed to relate to the plural. The word “exemplary” is used herein to mean “serving as an example, instance or illustration”. Any embodiment described as “exemplary” is not necessarily to be construed as preferred or advantageous over other embodiments and / or to exclude the incorporation of features from other embodiments. The word “optionally” is used herein to mean “is provided in some embodiments and not provided in other embodiments”. It is appreciated that certain features of the present disclosure, which are, for clarity, described in the context of separate embodiments, may also be provided in combination in a single embodiment. Conversely, various features of the present disclosure, which are, for brevity, described in the context of a singleembodiment, may also be provided separately or in any suitable combination or as suitable in any other described embodiment of the disclosure.

Claims

CLAIMSWe Claim:

1. A data processing system (100) for data security enhancement, the data processing system (100) comprises: a processor (114) configured to: identify a plurality of tenants (104) in a multitenant software-as-a-service (SaaS) environment (102), wherein the data processing system (100) is configured to operate in the multitenant SaaS environment (102); generate a unique encoding scheme for each tenant of the plurality of tenants (104) identified in the multitenant SaaS environment (102); encode each tenant’s data structure using the generated unique encoding scheme; and store data associated with each tenant in form of the encoded data structure in a database (108); wherein encoded data structure of a first tenant (302A) of the plurality of tenants (104) is indecipherable to a second tenant (302B) of the plurality of tenants (104) and encoded data structure of the second tenant (302B) is indecipherable to the first tenant (302 A).

2. The data processing system (100) as claimed in claim 1, wherein data associated with each tenant comprises time-series data which corresponds to sensor data captured by Internet of Things (loT) devices.

3. The data processing system (100) as claimed in claim 1, wherein generation of the unique encoding scheme comprises generation of a hierarchical node identifier structure for representing components of a system associated with the time-series data, wherein the hierarchical node identifier structure comprises identifiers for devices, parameters and alarms of the system.

4. The data processing system (100) as claimed in claim 3, wherein the processor (114) is further configured to store data associated with eachtenant in form of the encoded data structure in the database (108) using the hierarchical node identifier structure.

5. The data processing system (100) as claimed in claim 1, wherein the processor (114) is further configured to dynamically generate the unique encoding scheme for each tenant’s data structure.

6. The data processing system (100) as claimed in claim 1, wherein the data processing system (100) further comprises a user interface (110) configured to enable each tenant of the plurality of tenants (104) to access and view the encoded data structure associated with the respective tenant.

7. The data processing system (100) as claimed in claim 1, wherein the processor (114) is further configured to provide each tenant with a capability to decode the encoded data structure associated with the respective tenant.

8. The data processing system (100) as claimed in claim 1, wherein the processor (114) is further configured to generate a unique encoding scheme for data encoding of each tenant of the plurality of tenants (104) identified in the multitenant SaaS environment (102).

9. The data processing system (100) as claimed in claim 1, wherein the processor (114) is further configured to monitor access to the encoded data structure and generate alarms in case of unauthorized access attempts.

10. A method (200) for data security enhancement, comprising: identifying, by a processor (114), a plurality of tenants (104) in a multitenant software-as-a-service (SaaS) environment (102); generating, by the processor (114), a unique encoding scheme for each tenant of the plurality of tenants (104) identified in the multitenant SaaS environment (102); encoding, by the processor (114), each tenant’s data structure using the generated unique encoding scheme; andstoring, by the processor (114), data associated with each tenant in form of the encoded data structure in a database (108), wherein encoded data structure of a first tenant (302A) of the plurality of tenants (104) is indecipherable to a second tenant (302B) of the plurality of tenants (104) and encoded data structure of the second tenant (302B) is indecipherable to the first tenant (302 A).

Citation Information

Patent Citations

  • Single sign-on and single logout functionality for a multi-tenant identity and data security management cloud service

    EP3528454B1

  • Systems and methods of database encryption in a multitenant database management system

    US11238174B2