Multi-tenant Data Protection System with Logical Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current data protection solutions for large enterprises and cloud service providers lack scalability, logical isolation, and efficient management, failing to provide centralized access and management for multiple tenants while maintaining data redundancy.

Innovation Solution

A scalable multi-tenant data protection system that utilizes a master database and tenant-specific databases, along with data protection engines to create and manage redundant data stores, providing per-tenant data redundancy and centralized management through a shared user interface and business logic module.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a single-tenant data protection system is used for each tenant separately, then data isolation and security are improved, but hardware and software costs increase significantly

Engineering Contradiction:
Improvedata isolationVSAvoidhardware and software costs
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent combines multiple tenant data protection operations into a single shared application instance. The data protection application server hosts multiple tenant databases and handles data protection requests from multiple tenants concurrently, eliminating the need for separate application servers for each tenant. This merging approach maintains data isolation through database-level separation while significantly reducing hardware and software costs.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The data protection application server is designed with universal functionality to serve multiple tenants. The single application instance can authenticate users from different tenants, manage their respective databases, and perform data protection operations for all tenants. This multi-functional design allows one system to replace multiple dedicated systems.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If separate data protection systems are deployed for each tenant, then data security and isolation are improved, but system complexity and management difficulty increase

Engineering Contradiction:
Improvedata securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges multiple tenant management functions into a single data protection application instance. The application server maintains multiple tenant databases and handles authentication, authorization, and data protection operations for all tenants through a unified interface. This consolidation reduces system complexity by eliminating the need to deploy and manage separate application servers for each tenant.

Inventive Principle:
Principle #5Merging (Combining)

3Device complexity

If a shared data protection application serves multiple tenants, then cost and complexity are reduced, but data isolation and security may be compromised

Engineering Contradiction:
Improvesystem complexityVSAvoiddata isolation
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent segments tenant data into separate, isolated databases within the shared application system. Each tenant has their own database (e.g., tenant1_database, tenant2_database) that is logically isolated from other tenants. The data protection application authenticates users and enforces access controls to ensure that tenants can only access their own data, maintaining data isolation while using a shared application infrastructure.

Inventive Principle:
Principle #1Segmentation

4Reliability

If traditional data protection applications are used, then basic data redundancy is provided, but scalability to serve large enterprises with multiple tenants is limited

Engineering Contradiction:
Improvedata redundancyVSAvoidscalability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The data protection application is designed with universal functionality to serve multiple tenants simultaneously. The application server can authenticate users from different organizations, manage their respective databases, and perform data protection operations for all tenants through a single instance. This multi-functional design enables the system to scale from serving a single tenant to serving large enterprises with multiple tenants without requiring proportional increases in infrastructure.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11151270B2Systems and methods for multi-tenant data protection application
Publication Date: 2021.10.19 NAKIVO
  • US11151270B2 patent drawing
  • US11151270B2 patent drawing
  • US11151270B2 patent drawing

AI summary

A system for providing a multi-tenant data protection application includes a server shared by all tenants for access to the provided multi-tenant data protection application. The system further includes business logic for managing tenants of the multi-tenant data protection application, tenant resource allocation and isolation of tenant operating environments. The system additionally includes a database server for creating, managing and maintaining databases, including a master database used to store configuration and monitoring data which is used for tenant management and monitoring, and a plurality of private tenant databases, each used to store tenant-specific configuration, tenant-specific data and associated tenant resources. The system includes one or more data protection engines configured to store a copy of protected data at tenant redundant data stores.