Hierarchical Multi-Tenant Service Access via AFID Name-Spaces
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing communication systems face inefficiencies in accessing services due to the lack of a structured approach to directly access services in the core network, leading to wasted device resources such as power, memory, and processing resources.
Innovation Solution
The system and method implement a hierarchical multi-tenant architecture that maps services to specific tenant profiles, allowing access through a hierarchical tier structure comprising a tenant tier, a department tier, and an API tier, using an Application Function Identifier (AFID) that includes a tenant ID, department ID, and API ID.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If user devices attempt to access services without a structured approach, then services can be accessed, but device resources (power, memory, processing) are wasted due to searching and scrolling through services
Solution Approach 1:
The patent segments the service access process into distinct hierarchical levels (tenant tier, department tier, API tier) with corresponding identifier components (tenant ID, department ID, API ID). This segmentation allows the system to directly route service requests without requiring devices to search through all available services, thereby improving access efficiency and reducing device resource consumption.
2Reliability
If a hierarchical multi-tenant architecture with name-spaces is implemented, then access control and service mapping are improved, but system complexity increases
Solution Approach 1:
The patent implements a nested hierarchical structure where tenant profiles contain multiple departments, and departments contain multiple services. Each level has its own identifier (tenant ID, department ID, API ID) that nests within the previous level. This nesting provides precise access control at each level while maintaining a structured, manageable architecture through the use of name-spaces that isolate different tenant environments.
Solution Approach 2:
The patent introduces an intermediary mapping mechanism that translates the hierarchical identifier structure (AFID combining tenant ID, department ID, and API ID) into corresponding name-spaces and service routes. This intermediary layer simplifies access control by automatically routing requests based on the hierarchical identifiers without requiring complex device-side logic, thus improving reliability while managing system complexity.
3Adaptability or versatility
If services are shared across multiple tenants and departments, then resource utilization improves, but access control and permission management become more difficult
Solution Approach 1:
The patent creates a universal hierarchical identifier structure (AFID) that can represent any service access scenario across multiple tenants and departments. The same three-component structure (tenant ID, department ID, API ID) universally applies whether a service is shared across one department, multiple departments, or multiple tenants, providing versatility while maintaining consistent access control rules at each hierarchical level.
Data Source
AI summary
An apparatus comprises a memory and a processor communicatively coupled to one another. The memory may be configured to store one or more directories comprising access to multiple tenant profiles and one or more network access commands configured to provide access to one or more entitlements. Each tenant profile of the tenant profiles are associated with one or more services. The processor may be configured to receive a request to access at least one service. The request comprises an application function identifier (AFID). The tenant ID references a tenant profile of the tenant profiles. The department ID references multiple entitlements associated with the tenant profile. The API ID references a service associated with the entitlements. Further, the processor may be configured to determine multiple network access commands configured to enable access to the service in accordance with the entitlements and generate a report comprising the network access commands.


