Cloud Access Boundaries for Multi-Tenant Data Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cloud data centers face security threats to tenant data due to attacks from external attackers, unauthorized access by other tenants, and internal malicious activities, necessitating a robust access management system.

Innovation Solution

A cloud computing technology-based access management method and apparatus that allows tenants to establish data boundaries with customizable constraint conditions for identity subjects, access resources, network usage, device types, and trusted execution environments, ensuring that only authorized access requests are granted.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If cloud data centers provide services for multiple tenants and public network, then service coverage and resource utilization are improved, but security threats to tenant data increase

Engineering Contradiction:
Improveservice coverageVSAvoidsecurity threats
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the cloud data center into isolated data boundaries for each tenant. Each tenant's data is enclosed in a separate boundary with its own access control policies, preventing cross-tenant access while allowing the cloud platform to serve multiple tenants simultaneously. This resolves the contradiction by enabling multi-tenant service coverage while protecting each tenant's data through spatial and access segmentation.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a cloud platform as an intermediary layer between tenants and the underlying infrastructure. The cloud platform establishes and manages data boundaries, enforcing access control policies that prevent direct access to tenant data. This intermediary mechanism enables the cloud platform to provide services to multiple tenants while maintaining security through policy enforcement at the boundary layer.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If traditional access control methods are used in cloud environments, then implementation simplicity is maintained, but security effectiveness against cloud-specific threats deteriorates

Engineering Contradiction:
Improveimplementation simplicityVSAvoidsecurity effectiveness
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements preliminary action by establishing data boundaries and access control policies before any data access occurs. The cloud platform pre-configures boundary conditions, identity subject restrictions, and resource access rules for each tenant. When access requests are made, the pre-established boundaries automatically enforce security without requiring complex real-time evaluation, thus maintaining implementation simplicity while improving security effectiveness.

Inventive Principle:
Principle #10Preliminary action

3Measurement precision

If detailed access control policies are implemented for each tenant, then security precision is improved, but system complexity increases

Engineering Contradiction:
Improveaccess control precisionVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent applies local quality by allowing each tenant to have customized access control policies within their own data boundary, while the overall system maintains a standardized boundary enforcement mechanism. Each tenant's boundary has specific identity subject constraints, resource access rules, and operation restrictions tailored to their needs, but the cloud platform enforces all boundaries using a unified approach, thus achieving high access control precision without proportionally increasing system complexity.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS20260075056A1Cloud Computing Technology-Based Access Management Method and Apparatus, and Device
Publication Date: 2026.03.12 HUAWEI CLOUD COMPUTING TECHNOLOGIES CO LTD
  • US20260075056A1 patent drawing
  • US20260075056A1 patent drawing
  • US20260075056A1 patent drawing

AI summary

A cloud computing technology-based access management method includes a cloud platform that receives a data boundary establishment request from a first tenant for a cloud service; the cloud platform establishes the data boundary for the cloud service; the cloud platform compares information carried in an access request, for the cloud service, that is received by the cloud service with the constraint condition in the data boundary; and the cloud platform allows the cloud service to respond to the access request when the information carried in the access request matches the constraint condition in the data boundary.