Multi-tenant Cloud Resource Pool Segmentation for Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current Platform-as-a-Service (PaaS) offerings face inefficiencies due to the need for significant expertise and resources to manage web applications across different hypervisors and cloud providers, leading to costly and resource-intensive virtual machine (VM) management, especially when multiple customers' applications are deployed on separate VMs, which can result in underutilization of resources.

Innovation Solution

A method for command execution in a multi-tenant cloud hosting environment where a broker layer coordinates actions across multiple resource pools and nodes, allowing multiple applications from different owners to share resources while maintaining security and segregation through techniques like SELinux security labeling and Linux control groups, enabling efficient resource utilization and simplified application management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple customers' applications are deployed on separate VMs, then security and isolation are improved, but resource utilization deteriorates and costs increase

Engineering Contradiction:
Improvesecurity and isolationVSAvoidresource utilization
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system segments the VM into isolated resource pools using Linux control groups (cgroups) and SELinux security labels. Each customer's application components are assigned to specific resource pools with dedicated CPU, memory, and I/O resources, ensuring security and isolation while sharing the same physical VM. This segmentation allows multiple customers to coexist on a single VM without resource contention or security breaches.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent merges multiple customers' applications onto a single VM, combining resources that would otherwise be wasted in separate VMs. By using resource pools and orchestration, the system efficiently packs multiple applications together, improving overall resource utilization and reducing the total number of VMs needed, while maintaining security through isolation mechanisms.

Inventive Principle:
Principle #5Merging (Combining)

2Reliability

If a VM is sized to accommodate a single application, then application performance is improved, but resource utilization deteriorates when the application does not fully utilize the VM resources

Engineering Contradiction:
Improveapplication performanceVSAvoidwasted computational resources
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The system dynamically allocates resources within the VM to different applications based on their actual needs and performance requirements. The orchestration layer can adjust resource pool configurations, CPU shares, memory limits, and I/O priorities dynamically, allowing applications to receive appropriate resources without over-provisioning. This dynamic allocation ensures application performance while minimizing wasted resources.

Inventive Principle:
Principle #15Dynamics

3Productivity

If applications are deployed across multiple nodes for distribution, then scalability and fault tolerance are improved, but command coordination and management complexity increase

Engineering Contradiction:
Improvescalability and fault toleranceVSAvoidcommand coordination complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary orchestration layer that manages command coordination across distributed applications and nodes. This intermediary receives customer commands, determines which resource pools and application components are affected, and coordinates execution across multiple nodes. This abstraction layer simplifies command management while maintaining the scalability and fault tolerance benefits of distributed deployment.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS9245111B2Owner command execution in a multi-tenant cloud hosting environment
Publication Date: 2016.01.26 RED HAT INC
  • US9245111B2 patent drawing
  • US9245111B2 patent drawing
  • US9245111B2 patent drawing

AI summary

A owner command to an application hosted by a platform as a service (PaaS) system can be performed, in one embodiment, by receiving the command from the authenticated owner at a first resource pool containing a first application component of the application, wherein the first node hosts a plurality of resource pools each containing application components belonging to different application owners. A second resource pool associated with the application is then identified, the second resource pool being hosted on a second node and containing a second application component of the application. The, a command implementation sequence defining the implementation of the received command over multiple application components is executed by performing a first action on the first application component on the first node and performing a second action on the second application component on the second node.