Layered Multi-Tenant Architecture Using Cloud Container Namespace Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional multi-tenant systems face complexity in creating multiple tenants for a single customer, lacking the ability to provide layered multi-tenancy, which is essential for highly regulated customers with security and regulatory constraints, and are not portable across different environments.

Innovation Solution

A method and system for creating a layered multi-tenant architecture using a cloud container with a namespace created via Container as a Service (CaaS) platforms, providing logical isolation at the database layer and allowing access through APIs with web tokens, enabling multiple tenants based on business units and supporting portability across environments.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If traditional multi-tenant system creates one tenant for one customer, then security isolation is maintained, but the ability to create multiple tenants for one customer is lost

Engineering Contradiction:
Improveability to create multiple tenants per customerVSAvoidcomplexity of creating multiple tenants
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the multi-tenant architecture into multiple isolation layers: cloud container level (first layer) and database namespace level (second layer). This segmentation allows a single customer to have multiple tenants created through different business units, each with appropriate isolation, resolving the contradiction between versatility and complexity by providing structured multi-tenancy capability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a second dimension of multi-tenancy by adding database-level namespace isolation alongside cloud container isolation. This dimensional addition enables multiple tenants per customer without increasing operational complexity, as the system manages isolation across two independent layers simultaneously.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Reliability

If cloud container namespace is created for first layer isolation, then security segregation is improved, but portability across environments is reduced

Engineering Contradiction:
Improvesecurity segregationVSAvoidportability across environments
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments isolation mechanisms into two independent layers: cloud container namespaces for first-layer security segregation and database-level namespaces for second-layer isolation. This segmentation maintains strong security boundaries while improving portability, as each layer can be configured independently for different deployment environments.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system dynamically manages namespace creation and configuration at both cloud container and database levels, allowing the same multi-tenant architecture to adapt to different deployment environments (cloud, on-premise, air-gapped) while maintaining security segregation through consistent namespace isolation principles.

Inventive Principle:
Principle #15Dynamics

3Reliability

If logical isolation at database layer is implemented, then data security is improved, but system complexity increases

Engineering Contradiction:
Improvedata securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments data isolation into two distinct layers: cloud container-level isolation for application-level security and database-level namespace isolation for data-level security. This segmentation improves data security by ensuring isolation at both layers while managing complexity through clear separation of concerns, where each layer handles specific isolation requirements independently.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11513834B1Creating a layered multi-tenant architecture
Publication Date: 2022.11.29 REGSCALE
  • US11513834B1 patent drawing
  • US11513834B1 patent drawing
  • US11513834B1 patent drawing

AI summary

Disclosed is a system and a method for creating a layered and portable multi-tenant architecture. Initially, a cloud container for a platform is created. The cloud container includes a namespace for a tenant accessing the platform. Further, a logical isolation for the namespace of the tenant is created. Subsequently, a plurality of tenants in the namespace is generated based on the logical isolation. The tenant is further allowed to access a tenant database via Application Programming Interfaces (APIs), thereby creating a layered multi-tenant architecture.