Administrative Tenancy Access for Cloud Sovereignty Compliance

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cloud computing systems face challenges in complying with sovereignty requirements that mandate user access to be restricted to specific geographic locations, necessitating innovative solutions to ensure compliance with national laws, security standards, and strategic interests.

Innovation Solution

Implementing an administrative tenancy within cloud environments that enforces sovereignty requirements by geolocation checks and user authentication, using virtual private networks and hardware security devices, while maintaining audit logs of user access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If cloud environments implement sovereignty requirements by restricting user access to specific geographic locations, then compliance with national laws and security standards is improved, but system complexity increases due to geolocation checks and authentication mechanisms

Engineering Contradiction:
Improvecompliance with sovereignty requirementsVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an administrative tenancy as an intermediary layer between users and cloud resources. This administrative tenancy contains geolocation checking and authentication services that mediate access requests, enforcing sovereignty requirements without requiring complex modifications to the underlying cloud infrastructure. The administrative tenancy acts as a policy enforcement point that simplifies the overall system architecture while maintaining compliance.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the cloud environment into multiple tenancies, including administrative tenancies and customer tenancies. Each tenancy can have independent access policies and geolocation restrictions. This segmentation allows sovereignty requirements to be enforced in specific administrative tenancies without affecting the entire cloud system, thereby managing complexity through modular isolation of policy enforcement functions.

Inventive Principle:
Principle #1Segmentation

2Reliability

If cloud environments enforce geolocation restrictions and user authentication, then security and regulatory adherence are enhanced, but ease of operation deteriorates due to additional access restrictions

Engineering Contradiction:
Improvesecurity and regulatory adherenceVSAvoidease of operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The administrative tenancy implements automated geolocation checking and authentication mechanisms that operate without manual intervention. The system automatically verifies user location and credentials against sovereignty requirements, eliminating the need for manual approval processes. This self-service approach maintains high security while minimizing the operational burden on users and administrators.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs geolocation checks and authentication preliminarily, before users attempt to access cloud resources. By pre-establishing access policies and verifying user eligibility in advance, the system prevents unauthorized access attempts rather than blocking them after initiation. This preliminary action reduces friction for authorized users while maintaining strict security controls.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If cloud environments use administrative tenancies with geolocation checks, then sovereignty compliance is achieved, but device complexity increases due to additional authentication and monitoring components

Engineering Contradiction:
Improvesovereignty complianceVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The administrative tenancy is designed as a universal platform that can enforce multiple sovereignty requirements simultaneously. A single administrative tenancy can implement geolocation restrictions, authentication policies, and audit logging for various cloud resources and customer tenancies. This multi-functional design consolidates what would otherwise require separate systems for each compliance requirement, reducing overall device complexity while maintaining comprehensive sovereignty compliance.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12609822B2Accessing cloud environments through administrative tenancies to comply with sovereignty requirements
Publication Date: 2026.04.21 ORACLE INT CORP
  • US12609822B2 patent drawing
  • US12609822B2 patent drawing
  • US12609822B2 patent drawing

AI summary

Techniques for providing user access to cloud environments through an administrative tenancy to comply with sovereignty requirements are disclosed. The administrative tenancy is one of multiple tenancies in the cloud environment. The administrative tenancy includes tools for communicating with services running outside of the administrative tenancy. The user may only be able to access these services through the administrative tenancy. User access to the administrative tenancy requires the user to satisfy one or more sovereignty requirements. After determining that the user satisfies the sovereignty requirements for the cloud environment, the system grants the user access to the tools within the administrative tenancy to communicate with services outside the administrative tenancy.