Hierarchical Isolate Tags for Multi-Tenant Cloud Storage Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current cloud storage services face challenges in providing high-level logical isolation and access control, especially for regulated tenants with multiple clients and data sources, to ensure authorized access and compliance with regulations like HIPAA, GDPR, and Gramm-Leach-Bliley.
Innovation Solution
The implementation of hierarchical tags (client tag, tenant tag, and data source tag) to authenticate and authorize access to data sources, allowing users to access specific isolated zones dynamically, without requiring additional infrastructure, by using a multi-tenancy configuration registry and encryption for secure access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional authentication methods (user identifier and password) are used to control access to cloud storage services, then basic access control is achieved, but high-level logical isolation and data protection for regulated tenants cannot be ensured
Solution Approach 1:
The patent segments the authentication system into multiple hierarchical levels: organization level, tenant level, and data source level. Each level has its own isolate tag that collectively provides comprehensive access control. This segmentation allows basic authentication to remain simple while adding layered security for regulated tenants without significantly increasing overall system complexity.
Solution Approach 2:
The patent introduces isolate tags as intermediary elements between users and data sources. These tags act as mediators that carry organization, tenant, and data source identifiers, enabling the system to verify multi-level authorization without requiring complex authentication protocols. The isolate tag serves as a lightweight intermediary that simplifies the access control mechanism while ensuring high-level logical isolation.
2Reliability
If strict isolation is implemented to comply with regulations like HIPAA, GDPR, and Gramm-Leach-Bliley, then data protection is improved, but access control flexibility and scalability are reduced
Solution Approach 1:
The patent implements dynamic access control through isolate tags that can be assigned and revoked programmatically. The hierarchical structure allows organizations to dynamically adjust access permissions across multiple tenants and data sources without manual reconfiguration. This dynamic approach maintains strict isolation for compliance while providing flexibility to adapt to changing regulatory requirements and business needs.
Solution Approach 2:
The isolate tag mechanism serves multiple functions simultaneously: it provides authentication, authorization, audit trail capability, and regulatory compliance verification. This multi-functional approach allows a single mechanism to handle various access control requirements across different regulations (HIPAA, GDPR, Gramm-Leach-Bliley) without requiring separate systems, thereby maintaining flexibility while ensuring compliance.
3Productivity
If multiple tenants and data sources are managed within a single cloud storage service, then resource utilization and scalability are improved, but the complexity of managing isolation and access control increases
Solution Approach 1:
The patent implements a nested hierarchical structure where organization identifiers contain tenant identifiers, which in turn contain data source identifiers within isolate tags. This nesting approach allows multiple tenants and data sources to be managed within a single cloud storage service in a structured manner. The nested organization simplifies management by providing a clear hierarchy that automatically enforces isolation while maintaining scalability and high resource utilization.
Data Source
AI summary
Provided are a computer program product, system, and method for providing access to data storage services in a network environment. Multi-tenancy information for each of a plurality of clients has at least one tenant assigned to the client, at least one data source assigned to the tenant assigned to the client, and for each of the at least one data source, information on at least one user assigned to the data source and permitted access to the data source. A user is provided an isolate tag comprising a client tag identifying one client, a tenant tag identifying one tenant, and a data source tag identifying one data source to which the user is permitted to access data. A user access request with an isolate tag is processed in response to determining that the multi-tenancy information indicates that the client, tenant, and data source identified by the isolate tag are related.


