Dual Level Multi-Tenancy for AI Cloud Service Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In conventional single level tenancy paradigms, artificial intelligence (AI) service providers face excessive time and resource consumption in creating and maintaining cloud access control resources, and duplicative efforts are made in implementing identical cloud access features, hindering the cloud-based deployment of AI content.
Innovation Solution
A dual level tenancy approach is implemented where an AI core platform supports shared cloud access control resources, allowing AI service provider tenants to access and utilize these resources for onboarding, authentication, and metering, reducing the need for individual service providers to create and maintain their own resources.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If AI service providers implement single level tenancy with individual cloud access control resources, then each provider can maintain full control and security, but resource consumption and time expenditure increase excessively
Solution Approach 1:
Multiple AI service providers share common cloud access control resources (service brokers, authentication services, metering services) through a multi-tenancy architecture. Instead of each provider maintaining separate instances, they consolidate these resources into shared infrastructure that serves multiple tenants simultaneously, reducing overall resource consumption and deployment time.
Solution Approach 2:
The cloud access control resources are designed to serve multiple AI service providers and their respective tenants through a universal service broker framework. The service brokers implement multi-tenancy to handle authentication, authorization, and metering for different providers and tenants using the same infrastructure, making the system universally applicable across multiple organizations.
2Reliability
If AI service providers create individual cloud access control resources, then security and access control are maintained, but duplicative efforts increase resource consumption
Solution Approach 1:
The patent consolidates duplicate authentication services, service brokers, and metering services into shared multi-tenant instances. Multiple AI service providers and their tenants share these security infrastructure components, eliminating the need for each provider to create and maintain separate instances, thereby reducing resource consumption while preserving security through proper multi-tenancy isolation.
3Adaptability or versatility
If individual service brokers are created for each AI service provider, then provider-specific control is maintained, but device complexity and setup time increase
Solution Approach 1:
The service broker functionality is segmented into modular components that can be shared across multiple tenants. Each AI service provider gets dedicated logical access and control over their specific tenants and resources through the shared service broker infrastructure, while the underlying complexity is abstracted away. The service broker implements multi-tenancy to provide provider-specific control without requiring individual broker instances.
4Adaptability or versatility
If AI service providers implement their own authentication and metering services, then service autonomy is maintained, but productivity and deployment efficiency decrease
Solution Approach 1:
The multi-tenant service broker framework enables AI service providers to onboard tenants and manage access without manually configuring separate authentication and metering infrastructure for each provider. The shared service brokers automatically handle authentication, authorization, and usage metering for multiple providers and tenants, allowing providers to focus on their AI services rather than infrastructure setup, thereby improving deployment efficiency while maintaining service autonomy.
Data Source
AI summary
A method for exposing artificial intelligence content as a cloud service may include onboarding, by a service broker of a core platform hosting an artificial intelligence (AI) resource, a service provider tenant providing the artificial intelligence resource. The onboarding of the first service provider tenant includes creating, at the core platform, a function specific service broker associated with the artificial intelligence resource. The function specific service broker may then onboard one or more service consumer tenants for accessing the artificial intelligence resource associated with the first provider tenant. Moreover, in response to the one or more service consumer tenants accessing the artificial intelligence resource, the function specific service broker may authenticate the one or more service consumer tenants and meter a usage of the artificial intelligence resource by the one or more service consumer tenants. Related methods and computer program products are also disclosed.


