Multi-tenant Secrets Policy Enforcement via Intermediary Mediation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In multi-tenant computing environments, service providers face challenges in managing tenant secrets policies that differ from their own security policies, leading to potential security risks and logistical complexities in ensuring secure data sharing among tenants.

Innovation Solution

A system and method for managing tenant secrets policies, where tenant computing environments store and manage their own secrets and policies, with a service provider computing environment overseeing and authorizing policy implementations, ensuring compliance with both tenant and service provider security standards, and enabling secure sharing of secrets between tenants when authorized.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If tenants manage their own secrets policies independently, then security compliance with tenant-specific requirements is improved, but system complexity and coordination overhead increase

Engineering Contradiction:
Improvesecurity complianceVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments secrets management into tenant-specific policy modules that can be independently configured and enforced. Each tenant's secrets policy is a separate enforceable rule set that operates autonomously within the multi-tenant environment, allowing customized security requirements while maintaining overall system coordination through the policy enforcement mechanism.

Inventive Principle:
Principle #1Segmentation

2Ease of operation

If service provider enforces uniform security policies across all tenants, then system management simplicity is improved, but tenant-specific security requirements cannot be met

Engineering Contradiction:
Improvesystem management simplicityVSAvoidtenant-specific security requirements
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The policy enforcement mechanism serves multiple functions: it enforces service provider baseline security policies universally across all tenants while simultaneously supporting tenant-specific secrets policies. The same enforcement infrastructure handles both uniform and customized security requirements, eliminating the need for separate management systems.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Productivity

If tenants share secrets in multi-tenant environment, then collaboration efficiency is improved, but security risks from unauthorized access increase

Engineering Contradiction:
Improvecollaboration efficiencyVSAvoidsecurity risks
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The service provider's policy enforcement mechanism acts as an intermediary between tenants sharing secrets. It mediates access control by evaluating tenant secrets policies against service provider security requirements, allowing authorized collaboration while blocking unauthorized access attempts. This intermediary layer enables secure secret sharing without direct tenant-to-tenant exposure.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP3138035B1Method and apparatus for multi-tenancy secrets management
Publication Date: 2018.12.19 INTUIT INC
  • EP3138035B1 patent drawingFigure 1
  • EP3138035B1 patent drawingFigure 2
  • EP3138035B1 patent drawingFigure 3

AI summary

A service provider computing environment includes a service provider secrets policy. A service provider computing device receives tenant secrets policies from tenants. The tenants are tenants of multi-tenant assets of a service provider. The service provider computing environment determines of the tenant secrets policies satisfy the requirements of the service provider secrets policy. If the tenant secrets policies satisfy the requirements of the service provider secrets policy, the service provider computing environment allows the tenant secrets policies to be applied to tenant data or information in the multi-tenant assets.