Layered Multi-Tenant Architecture Using Cloud Container Namespace Isolation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional multi-tenant systems face complexity in creating multiple tenants for a single customer, lacking the ability to provide layered multi-tenancy, which is essential for highly regulated customers with security and regulatory constraints, and are not portable across different environments.
Innovation Solution
A method and system for creating a layered multi-tenant architecture using a cloud container with a namespace created via Container as a Service (CaaS) platforms, providing logical isolation at the database layer and allowing access through APIs with web tokens, enabling multiple tenants based on business units and supporting portability across environments.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If traditional multi-tenant system creates one tenant for one customer, then security isolation is maintained, but the ability to create multiple tenants for one customer is lost
Solution Approach 1:
The patent segments the multi-tenant architecture into multiple isolation layers: cloud container level (first layer) and database namespace level (second layer). This segmentation allows a single customer to have multiple tenants created through different business units, each with appropriate isolation, resolving the contradiction between versatility and complexity by providing structured multi-tenancy capability.
Solution Approach 2:
The patent introduces a second dimension of multi-tenancy by adding database-level namespace isolation alongside cloud container isolation. This dimensional addition enables multiple tenants per customer without increasing operational complexity, as the system manages isolation across two independent layers simultaneously.
2Reliability
If cloud container namespace is created for first layer isolation, then security segregation is improved, but portability across environments is reduced
Solution Approach 1:
The patent segments isolation mechanisms into two independent layers: cloud container namespaces for first-layer security segregation and database-level namespaces for second-layer isolation. This segmentation maintains strong security boundaries while improving portability, as each layer can be configured independently for different deployment environments.
Solution Approach 2:
The system dynamically manages namespace creation and configuration at both cloud container and database levels, allowing the same multi-tenant architecture to adapt to different deployment environments (cloud, on-premise, air-gapped) while maintaining security segregation through consistent namespace isolation principles.
3Reliability
If logical isolation at database layer is implemented, then data security is improved, but system complexity increases
Solution Approach 1:
The patent segments data isolation into two distinct layers: cloud container-level isolation for application-level security and database-level namespace isolation for data-level security. This segmentation improves data security by ensuring isolation at both layers while managing complexity through clear separation of concerns, where each layer handles specific isolation requirements independently.
Data Source
AI summary
Disclosed is a system and a method for creating a layered and portable multi-tenant architecture. Initially, a cloud container for a platform is created. The cloud container includes a namespace for a tenant accessing the platform. Further, a logical isolation for the namespace of the tenant is created. Subsequently, a plurality of tenants in the namespace is generated based on the logical isolation. The tenant is further allowed to access a tenant database via Application Programming Interfaces (APIs), thereby creating a layered multi-tenant architecture.


