Manufacturing Cloud Data Plane for Secure Multi-Tenant Sharing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current cloud-based industrial solutions face challenges such as data accessibility across data centers, security issues, and data sharing limitations due to architectural limitations of existing cloud platform architectures.
Innovation Solution
A multi-tenant Software-as-a-Service (SaaS) manufacturing platform with a service mesh system that uses metadata tagging and artificial intelligence to manage data access, security, and sharing across geographically distributed data centers, enabling secure and scalable data sharing and analysis.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If cloud-based industrial solutions are implemented across multiple data centers, then data accessibility and global coordination capability are improved, but security issues and data sharing limitations arise due to architectural constraints
Solution Approach 1:
The patent segments data into different types (operational data, business data, master data) and implements separate data planes for each type. Operational data uses a publish-subscribe model for real-time sharing, while business and master data use request-response models with stricter access controls. This segmentation allows different security policies to be applied to different data types, resolving the contradiction between accessibility and security.
Solution Approach 2:
The patent introduces a data plane as an intermediary layer between application layers and infrastructure. This data plane includes data type identification, data routing, and access control mechanisms that mediate data sharing requests. The intermediary enforces security policies while enabling data accessibility, resolving the contradiction by providing a controlled interface for data exchange.
2Productivity
If multi-tenant cloud architecture is used to serve multiple enterprises, then scalability and resource utilization are improved, but data sharing concerns and architectural complexity increase
Solution Approach 1:
The patent implements a universal data plane that handles multiple data types (operational, business, master data) and multiple communication patterns (publish-subscribe, request-response) through a single standardized interface. This multi-functional data plane reduces architectural complexity by providing a unified framework that serves multiple enterprises and data types, rather than requiring separate architectures for each scenario.
Solution Approach 2:
The patent adds a data plane dimension to the traditional cloud architecture stack. This new dimension provides specialized data handling capabilities between the application layer and infrastructure layer, allowing complex multi-tenant data sharing requirements to be addressed without complicating the existing application and infrastructure layers. The additional dimension absorbs the complexity of multi-tenant coordination.
3Productivity
If data sharing across customer entities is enabled, then operational efficiency and coordination are improved, but data security and access control requirements become more stringent
Solution Approach 1:
The patent applies different access control mechanisms to different data types based on their specific requirements. Operational data that benefits from real-time sharing uses publish-subscribe models with broader access, while business and master data use request-response models with stricter authorization checks. This local quality approach optimizes operational efficiency for suitable data types while maintaining security for sensitive data, without applying uniform complexity across all data.
Solution Approach 2:
The data plane acts as an intermediary that automatically enforces access control policies based on data type and user context. Rather than requiring complex access control logic in each application, the data plane mediates all data access requests, applying appropriate security rules transparently. This reduces access control complexity for applications while maintaining stringent security requirements.
Data Source
AI summary
A multi-tenant, cloud-based Software-as-a-Service (SaaS) manufacturing platform offers a variety of industrial applications to end customers—including but not limited to MES, ERP, quality management, supply chain management, and customer relationship management (CRM)—and implements associated architectural features that address a number of issues relating to data sharing, security, scalability, and other concerns.


