Hierarchical Isolate Tags for Multi-Tenant Cloud Storage Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cloud storage services face challenges in providing high-level logical isolation and access control, especially for regulated tenants with multiple clients and data sources, to ensure authorized access and compliance with regulations like HIPAA, GDPR, and Gramm-Leach-Bliley.

Innovation Solution

The implementation of hierarchical tags (client tag, tenant tag, and data source tag) to authenticate and authorize access to data sources, allowing users to access specific isolated zones dynamically, without requiring additional infrastructure, by using a multi-tenancy configuration registry and encryption for secure access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional authentication methods (user identifier and password) are used to control access to cloud storage services, then basic access control is achieved, but high-level logical isolation and data protection for regulated tenants cannot be ensured

Engineering Contradiction:
Improvedata protection and isolationVSAvoidaccess control system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the authentication system into multiple hierarchical levels: organization level, tenant level, and data source level. Each level has its own isolate tag that collectively provides comprehensive access control. This segmentation allows basic authentication to remain simple while adding layered security for regulated tenants without significantly increasing overall system complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces isolate tags as intermediary elements between users and data sources. These tags act as mediators that carry organization, tenant, and data source identifiers, enabling the system to verify multi-level authorization without requiring complex authentication protocols. The isolate tag serves as a lightweight intermediary that simplifies the access control mechanism while ensuring high-level logical isolation.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If strict isolation is implemented to comply with regulations like HIPAA, GDPR, and Gramm-Leach-Bliley, then data protection is improved, but access control flexibility and scalability are reduced

Engineering Contradiction:
Improveregulatory compliance and data isolationVSAvoidaccess control flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic access control through isolate tags that can be assigned and revoked programmatically. The hierarchical structure allows organizations to dynamically adjust access permissions across multiple tenants and data sources without manual reconfiguration. This dynamic approach maintains strict isolation for compliance while providing flexibility to adapt to changing regulatory requirements and business needs.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The isolate tag mechanism serves multiple functions simultaneously: it provides authentication, authorization, audit trail capability, and regulatory compliance verification. This multi-functional approach allows a single mechanism to handle various access control requirements across different regulations (HIPAA, GDPR, Gramm-Leach-Bliley) without requiring separate systems, thereby maintaining flexibility while ensuring compliance.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Productivity

If multiple tenants and data sources are managed within a single cloud storage service, then resource utilization and scalability are improved, but the complexity of managing isolation and access control increases

Engineering Contradiction:
Improveresource utilization and scalabilityVSAvoidmulti-tenancy management complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent implements a nested hierarchical structure where organization identifiers contain tenant identifiers, which in turn contain data source identifiers within isolate tags. This nesting approach allows multiple tenants and data sources to be managed within a single cloud storage service in a structured manner. The nested organization simplifies management by providing a clear hierarchy that automatically enforces isolation while maintaining scalability and high resource utilization.

Inventive Principle:
Principle #7Nested doll (Nesting)

Data Source

PatentUS11032263B2Provide access to data storage services in a network environment
Publication Date: 2021.06.08 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US11032263B2 patent drawing
  • US11032263B2 patent drawing
  • US11032263B2 patent drawing

AI summary

Provided are a computer program product, system, and method for providing access to data storage services in a network environment. Multi-tenancy information for each of a plurality of clients has at least one tenant assigned to the client, at least one data source assigned to the tenant assigned to the client, and for each of the at least one data source, information on at least one user assigned to the data source and permitted access to the data source. A user is provided an isolate tag comprising a client tag identifying one client, a tenant tag identifying one tenant, and a data source tag identifying one data source to which the user is permitted to access data. A user access request with an isolate tag is processed in response to determining that the multi-tenancy information indicates that the client, tenant, and data source identified by the isolate tag are related.