Hierarchical Identity Management for Multi-Tenant Application Configuration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current applications face challenges in being easily configured for various use cases, such as single-tenant or multi-tenancy scenarios, without requiring rearchitecting or developing different versions, especially when hosted on-premises or in the cloud by SaaS or MSPs, leading to limited diverse offerings and increased development costs.

Innovation Solution

The implementation of a hierarchical identity management (IDM) model that leverages the IDM models of tenants, allowing the application to be configured for multiple use cases without rearchitecting, including hard and soft partitioning scenarios, enabling efficient management and access control across different tenants and providers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of manufacture

If an application is configured for a specific usage scenario (single-tenant or multi-tenancy), then the application can be optimized for that scenario, but it requires rearchitecting or developing different versions for other scenarios

Engineering Contradiction:
Improveease of configurationVSAvoidapplication architecture complexity
Core Design Contradiction:
Ease of manufactureVSDevice complexity

Solution Approach 1:

The application is designed with a universal configuration framework that enables it to function across multiple usage scenarios (single-tenant, multi-tenancy, SaaS, on-premises, MSP-managed) without requiring separate versions or rearchitecting. The system uses a hierarchical identity management model that can be configured through parameters to adapt to different deployment scenarios, making the application multi-functional and scenario-agnostic.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If different versions of the application are developed for different usage scenarios, then each version can be optimized for its specific scenario, but development costs increase

Engineering Contradiction:
Improveusage scenario adaptabilityVSAvoiddevelopment resources
Core Design Contradiction:
Adaptability or versatilityVSQuantity of substance

Solution Approach 1:

The system enables different usage scenarios to be achieved by changing configuration parameters rather than developing different code versions. The hierarchical identity management model uses configurable parameters to adapt the application's behavior and structure to match different scenarios (single-tenant, multi-tenancy, SaaS, on-premises, MSP-managed), significantly reducing development resources while maintaining full adaptability.

Inventive Principle:
Principle #35Parameter changes

3Adaptability or versatility

If the application supports multiple usage scenarios through a single configuration, then diverse offerings are enabled, but the configuration complexity increases

Engineering Contradiction:
Improveusage scenario diversityVSAvoidconfiguration complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The configuration system is segmented into hierarchical layers (global configuration, tenant configuration, instance configuration) that can be independently managed. This segmentation allows complex multi-scenario support to be broken down into manageable configuration units, reducing overall configuration complexity while maintaining diverse scenario support through hierarchical composition.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A configuration intermediary layer is introduced that mediates between the application core and different usage scenario requirements. This intermediary handles the complexity of scenario-specific configurations by providing a standardized interface and translation layer, allowing the application to support diverse scenarios without exposing configuration complexity to users.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Ease of operation

If separate management tools are used for each customer in MSP scenarios, then customer-specific requirements are met, but management efficiency decreases

Engineering Contradiction:
Improvecustomer-specific management capabilityVSAvoidMSP management efficiency
Core Design Contradiction:
Ease of operationVSProductivity

Solution Approach 1:

The system merges multiple customer-specific management tools into a single unified application instance that can manage multiple tenants simultaneously. The hierarchical identity management model allows the MSP to access and manage different customer environments through one interface, combining the functionality of separate tools while maintaining customer-specific customization capabilities, thereby significantly improving management efficiency.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS20220263910A1Application configuration
Publication Date: 2022.08.18 MICRO FOCUS LLC
  • US20220263910A1 patent drawing
  • US20220263910A1 patent drawing
  • US20220263910A1 patent drawing

AI summary

An application managed by a provider is configured to run according to a selected usage scenario of a group of usage scenarios. The group of usage scenarios include a hard-partitioned usage scenario in which instances of the application are hard partitioned in correspondence with tenants of the provider. The group of usage scenarios include a soft-partitioned usage scenario in which the instances of the application are soft partitioned in correspondence with the tenants of the provider. The configured application is executed.