Multi-tenant Authorization Framework for Data Storage Clusters
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current data management and storage systems face challenges in efficiently managing and storing data across different virtual machine platforms, particularly in multi-tenant environments, where secure access and resource isolation are crucial, and data portability and backup/recovery are complex due to varying virtualization platforms and large compute infrastructures.
Innovation Solution
A data management and storage (DMS) cluster with peer nodes implements an authorization framework that scopes user access and privileges within a tenant organization, using a distributed data store and authorization tables to ensure secure access and resource isolation across different virtual machine platforms, allowing authorized actions on resources while preventing unauthorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If multiple organizations share a common compute infrastructure, then economies of scale are achieved, but tenant isolation and secure access become more complex
Solution Approach 1:
The patent implements tenant isolation by segmenting the compute infrastructure into logically separated tenant environments. Each tenant is assigned dedicated resources and access rights, allowing multiple organizations to share the physical infrastructure while maintaining logical separation. This segmentation enables secure access control without requiring complete infrastructure isolation.
Solution Approach 2:
The patent introduces an intermediary authorization framework that mediates between tenants and resources. This framework includes authorization tables and access control mechanisms that act as intermediaries, managing permissions and access rights between multiple organizations sharing the infrastructure. The intermediary layer simplifies the complexity of direct tenant-to-resource access control.
2Reliability
If user access is scoped to tenant organization resources, then secure access is ensured, but access control complexity increases
Solution Approach 1:
The patent implements a universal authorization framework that handles multiple access control scenarios through a single system. The authorization tables and access control mechanisms serve multiple functions: tenant isolation, user permission management, resource access control, and inheritance-based access. This multi-functionality reduces the need for separate access control mechanisms for each scenario.
Solution Approach 2:
The patent employs preliminary action by pre-defining authorization rules and access rights in authorization tables before users need access to resources. The system pre-establishes the authorization framework, tenant assignments, and access policies, so that when access requests are made, the system can quickly reference pre-configured rules rather than evaluating complex access control logic in real-time.
3Adaptability or versatility
If data portability across virtualization platforms is enabled, then flexibility is improved, but data management complexity increases
Solution Approach 1:
The patent addresses data portability by implementing parameter changes in the data management system. The system can change storage parameters, access protocols, and data formats to accommodate different virtualization platforms. By dynamically adjusting these parameters, the system enables data portability between platforms like VMware, Hyper-V, and KVM without requiring platform-specific management complexity.
Data Source
AI summary
A data management and storage (DMS) cluster of peer DMS nodes manages resources of a multi-tenant environment. The DMS cluster provides an authorization framework that provides user access which is scoped to the resources within a tenant organization and the privileges of the user within the organization. To authorize an action on a resource by a user, the DMS cluster determines determine user authorizations associated with the user defining privileges of the user on the resources of the multi-tenant environment, and organization authorizations associated defining resources of the multi-tenant environment that belong to the organization. The DMS cluster authorizes the action when the user authorizations and organizations authorized indicate that the action on the resource is authorized.


