Common Metadata Attribute for Multi-Tenant Data Isolation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing data management systems face challenges in efficiently isolating user data in multi-tenancy environments, requiring frequent changes to database tables and queries, and lack a simple, automated method for turning data separation on and off, especially when the number and content of dividers change over time.
Innovation Solution
Implementing a system that uses a common metadata attribute for data separation, allowing configuration through a visual interface without modifying standard objects or code, and automatically generating queries for data retrieval from isolated areas.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional user table with primary key is used for data isolation, then user data isolation is achieved, but flexibility to change data access permissions deteriorates
Solution Approach 1:
The patent segments data access control into two independent layers: (1) a static user table layer that provides reliable data isolation through primary keys, and (2) a dynamic configuration layer using common requisites that enables flexible permission changes. This segmentation allows each layer to fulfill its specific function without compromising the other.
Solution Approach 2:
The patent introduces common requisites as an intermediary mechanism between users and data. Instead of directly modifying user table permissions, the system uses common requisites as a mediator that can be dynamically configured to control data access, thereby maintaining isolation while enabling flexibility.
2Reliability
If multiple divider columns are added to tables for data separation, then data isolation capability is improved, but system complexity deteriorates
Solution Approach 1:
The patent merges the functionality of multiple divider columns into a single common requisite structure. Instead of adding separate columns to multiple tables, the system uses one common requisite that can be applied across different tables and objects, thereby reducing system complexity while maintaining data separation capability.
Solution Approach 2:
The common requisite serves multiple functions simultaneously: it acts as a divider column, a filtering mechanism, and a configuration parameter across different tables and objects. This multi-functionality eliminates the need for separate implementation in each table, reducing overall system complexity.
3Manufacturing precision
If manual code changes are made for data separation configuration, then precise control is achieved, but operational efficiency deteriorates
Solution Approach 1:
The patent implements self-service functionality where the system automatically generates and executes the necessary queries and code changes based on configuration parameters. The common requisite mechanism allows the system to self-configure data separation without requiring manual intervention, thereby maintaining precise control while dramatically improving operational efficiency.
Solution Approach 2:
The system performs preliminary configuration by pre-defining common requisites and their properties. When data separation is needed, the pre-configured requisites are automatically applied, eliminating the need for manual code changes at execution time and improving operational efficiency while maintaining precision.
4Ease of operation
If visual interface is used for data separation configuration, then ease of operation is improved, but automation capability deteriorates
Solution Approach 1:
The patent replaces manual mechanical configuration operations with automated electronic processes. The visual interface serves as a control panel that triggers automated query generation and execution, substituting manual code writing and table modification with automated system responses, thereby maintaining ease of operation while preserving automation capability.
Data Source
AI summary
A system for separation of data is provided. The data separation is implemented using a special data structure—a common attribute. The common attribute is a metadata object, which allows for using the same requisite for many configuration objects (directories, documents, charts of accounts, constants, etc.). A configuration developer can add and configure the common attributes in order not to change the standard objects and configurations. In other words, the developer does not need to add divider-columns into each table or other object. Instead, the developer can set a common attribute for some of the objects and control only this requisite.


