Multi-tenant Identity Service Platform for Secure Resource Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Multi-tenant software architectures face challenges in managing complex configurations, secure data access, and interoperability among entities, particularly when dealing with cross-jurisdictional transactions and compliance requirements, due to the complexity of sharing resources and data across multiple tenants.

Innovation Solution

A unified identity service platform that facilitates access to shared services and data across tenants, using hierarchical data structures and Agency and Regulation-as-a-Service (ARaaS) to manage policies, compliance, and transaction processing, enabling secure and compliant access to resources while accounting for regional rules and regulations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of energy

If multi-tenant software architecture is used to share applications and data across multiple entities, then resource utilization is optimized and costs are reduced, but complexity of managing configurations and secure access increases

Engineering Contradiction:
Improveresource utilizationVSAvoidconfiguration management complexity
Core Design Contradiction:
Loss of energyVSDevice complexity

Solution Approach 1:

The patent segments the multi-tenant system into distinct functional modules including identity services, policy management services, and tenant-specific service instances. Each module operates independently with well-defined interfaces, allowing complex configuration management to be divided into manageable segments that can be administered separately while maintaining overall system coherence and security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces intermediary components such as identity services and policy management services that act as mediators between tenants and shared resources. These intermediaries handle authentication, authorization, and configuration management centrally, reducing the complexity burden on individual tenants while enabling secure resource sharing across the multi-tenant environment.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Loss of energy

If multi-tenant architecture shares data and resources among tenants, then operational costs are reduced, but secure and reliable access to data and transaction services becomes problematic

Engineering Contradiction:
Improveoperational costVSAvoidsecure access reliability
Core Design Contradiction:
Loss of energyVSReliability

Solution Approach 1:

The patent implements local quality by providing tenant-specific configurations and access policies within the shared multi-tenant environment. Each tenant can have customized security parameters, data access rules, and service configurations tailored to their specific requirements, while still utilizing the shared infrastructure. This allows secure and reliable access control to be maintained at the tenant level without sacrificing the cost benefits of resource sharing.

Inventive Principle:
Principle #3Local quality

3Adaptability or versatility

If software applications are hosted by different businesses in multi-tenant architecture, then service variety is increased, but interoperability difficulties arise

Engineering Contradiction:
Improveservice varietyVSAvoidinteroperability complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements universality through standardized interfaces and common protocol layers that enable different service providers to interoperate within the multi-tenant system. The identity services and policy management framework provide universal mechanisms for authentication and authorization that work across diverse tenant applications, allowing service variety to increase while interoperability complexity is managed through standardization.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11586456B2Agency and regulation modeling for transactions in multi-tenant systems
Publication Date: 2023.02.21 PAYPAL INC
  • US11586456B2 patent drawing
  • US11586456B2 patent drawing
  • US11586456B2 patent drawing

AI summary

A method for applying agency and regulation modeling in a multi-tenant architecture system includes accessing merchant's representation in an identity manager. The merchant is managed via a full representation by an original identity manager. The method includes performing a first service for the merchant via the representation, and determining, based on results of the first service and on policies of the first service provider, that performance of a second service is required for completion of the first service. The second service is provided by a second service provider onboarded into the first service provider, where the second service amends policy requirements of the first service provider. The method includes accessing a first subservice of the second service using the representation to generate second results for use at a second subservice of the second service, the second subservice configured to use transaction resources of the first representation.