Cross-tenancy Compute Instance Attachment Mechanism

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cloud computing systems face challenges in allowing compute instances from different service tenancies to interact and communicate, as they are isolated due to being provisioned by separate infrastructures, making it difficult for customers to benefit from integrated resource utilization across different services.

Innovation Solution

An automated process is implemented to attach compute instances from different service tenancies, enabling communication and cooperative functioning by using a workflow that involves the control planes and identity management and authorization services, allowing for on-demand attachment and detachment of resources.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If compute instances are provisioned by separate service infrastructures in different tenancies, then service isolation and security are maintained, but communication and interaction between compute instances from different services are blocked

Engineering Contradiction:
Improveservice isolationVSAvoidcommunication between compute instances
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces an attachment mechanism that acts as an intermediary between compute instances from different service tenancies. This attachment creates a controlled communication channel that allows instances to interact while maintaining the underlying tenancy boundaries. The attachment includes authorization configurations that mediate access control, enabling communication without compromising service isolation or security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If compute instances from different service tenancies are allowed to interact, then resource integration and cooperation are improved, but system complexity and authorization management become more difficult

Engineering Contradiction:
Improveresource integrationVSAvoidauthorization management
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The attachment mechanism serves as an intermediary that simplifies authorization management by providing a standardized interface for cross-tenancy communication. Rather than managing complex direct authorization between multiple service infrastructures, the attachment abstracts this complexity into a single manageable object with built-in authorization policies.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The attachment mechanism provides universal functionality for enabling communication between any compute instances from different services, regardless of which specific service tenancies they originate from. This multi-functional approach allows a single mechanism to handle diverse cross-service communication scenarios without requiring service-specific customization.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If compute instances are strictly isolated by service tenancies, then security and control are maintained, but resource utilization efficiency and cooperative functionality are reduced

Engineering Contradiction:
Improvesecurity controlVSAvoidresource utilization efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The attachment mechanism introduces dynamic flexibility to the previously static tenancy isolation model. Attachments can be created and removed on-demand, allowing the system to dynamically adjust the level of isolation based on operational requirements. This enables compute instances to be isolated when security is paramount but connected when resource utilization efficiency is the priority.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS20240394627A1Attachment and detachment of compute instances owned by different tenancies
Publication Date: 2024.11.28 ORACLE INT CORP
  • US20240394627A1 patent drawing
  • US20240394627A1 patent drawing
  • US20240394627A1 patent drawing

AI summary

Techniques are disclosed for creating an attachment between two compute instances. An infrastructure and a generalized method is described for attaching two or more cloud resources (e.g., two compute instances) in spite of the compute resources being provisioned by two different services from different cloud tenancies. An automated process is described that is executed for wiring the compute instances. The automated process can be generally applied to attach any two compute instances providing two different services and provisioned from two different service tenancies.