Multi-Tenant MaaS Agent for On-Premises IT Data Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Small and medium-sized businesses (SMBs) face challenges in managing their on-premises IT systems due to limited time and expertise, and multi-tenancy in cloud services introduces security risks, making it difficult to efficiently manage and secure virtual infrastructures.

Innovation Solution

A Management-as-a-Service (MaaS) system with multi-tenancy features that assigns tenant identifiers to SMBs, enabling remote management and data isolation, using a multi-tenant database to store and manage IT data, and employing reverse session-origination tunnels for secure communication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If SMBs use on-premises IT systems with a responsible person, then the system can be managed locally, but the business operations suffer extended interruptions when the responsible person is unavailable

Engineering Contradiction:
Improvesystem availabilityVSAvoiddowntime during responsible person absence
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent introduces a cloud-based management platform as an intermediary between the on-premises IT system and the responsible person. This platform enables remote access and management capabilities, allowing the responsible person to manage IT systems from any location without causing business interruptions. The platform acts as a mediator that bridges the gap between local system requirements and remote management needs.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If SMBs migrate to cloud-based IaaS with multi-tenancy, then resource allocation efficiency improves, but security risks increase due to potential inter-infrastructure vulnerabilities

Engineering Contradiction:
Improveresource allocation efficiencyVSAvoidinter-infrastructure security risks
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent implements logical segmentation of multi-tenant environments through virtualization and isolation mechanisms. Each tenant's infrastructure is segmented into separate virtual containers that share physical resources but maintain independent security boundaries. This segmentation allows efficient resource allocation across tenants while preventing cross-tenant security breaches and vulnerabilities from propagating between infrastructures.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a platform-level security intermediary that mediates between multiple tenants and the underlying physical infrastructure. This intermediary layer provides unified security management, isolation enforcement, and vulnerability containment, allowing tenants to benefit from pooled resources and knowledge while protecting against inter-infrastructure security risks through centralized control and monitoring.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Object-affected harmful factors

If SMBs maintain on-premises IT systems, then security control is maintained, but the responsible person needs dedicated time and expertise that may be limited

Engineering Contradiction:
Improvesecurity controlVSAvoidmanagement burden on responsible person
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The patent implements self-service capabilities that allow the responsible person to perform IT management tasks remotely without requiring dedicated on-site time. The system enables automated monitoring, troubleshooting, and maintenance functions that reduce the manual effort and expertise required from the responsible person while maintaining security control through centralized management policies and automated security protocols.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10284631B2Management-as-a-service for on-premises information-technology systems
Publication Date: 2019.05.07 VMWARE INC
  • US10284631B2 patent drawing
  • US10284631B2 patent drawing
  • US10284631B2 patent drawing

AI summary

A Management-as-a-Service (MaaS) agent running on a SOPS creates collecting management statistics relating to the health, utilization, and performance of a subscriber on-premises system (SOPS). The MaaS agent forwards the collected data to a MaaS server, which stores the data in association with a tenant identifier (TID) in a multi-tenant database. The MaaS server tags user queries with the TID, so that the query result is based on management data for the respective SOPS, to the exclusion of SOPS associated with different TIDs. The use of multi-tenant techniques with non-multi-tenant SOPS allows one MaaS to manage plural SOPS while maintaining isolation of the management data for the respective SOPS. In addition, the use of multi-tenant techniques allows SOPS to be managed together with cloud-based subscriber applications, facilitating common management of hybrid cloud and on-premises systems.