Multi-Tenant Storage System with Container Isolation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional multi-tenant architectures face challenges in maintaining large databases, including difficulty in ensuring data consistency, managing rapid data growth, and preventing data leakage, which can lead to security breaches in threat detection applications.
Innovation Solution
A storage system that assigns each tenant separate containers for network information, with a multi-tenant management controller managing traffic and metrics to isolate and distribute containers across host computer systems, providing robust security and resiliency.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Use of energy by moving object
If a single database is used to store information from multiple tenants, then resource utilization is improved, but data security and isolation are worsened
Solution Approach 1:
The patent divides the single database into multiple isolated containers, each dedicated to a specific tenant. This segmentation allows multiple tenants to share the same physical infrastructure while maintaining complete data isolation, thus achieving both resource utilization and data security.
Solution Approach 2:
The patent introduces a multi-tenant management controller as an intermediary layer between tenants and the underlying database containers. This controller manages traffic routing, monitors metrics, and enforces isolation policies, enabling secure multi-tenant operation without requiring direct tenant access to each other's data.
2Quantity of substance
If a large distributed database is used to accommodate rapid data growth, then storage capacity is improved, but data consistency and management complexity are worsened
Solution Approach 1:
By segmenting the large distributed database into smaller, isolated container instances for each tenant, the patent simplifies consistency management within each container while allowing the overall system to scale. Each container maintains its own consistent data state independently.
Solution Approach 2:
Each tenant's container operates as a self-contained unit with its own data management capabilities, allowing independent data grooming, removal, and maintenance operations without affecting other tenants or requiring complex coordinated management across the entire distributed system.
3Productivity
If traditional multi-tenant architecture is used to share resources, then resource efficiency is improved, but security isolation and breach prevention are worsened
Solution Approach 1:
The patent implements strict segmentation by allocating separate database containers to each tenant, eliminating the shared-access security risks of traditional multi-tenant architectures while maintaining resource efficiency through the management controller's ability to allocate and manage physical resources across multiple isolated containers.
Solution Approach 2:
The multi-tenant management controller serves as a security intermediary that enforces isolation between containers, manages authenticated access, and prevents cross-tenant data access attempts, thereby achieving both resource efficiency and strong security isolation.
4Device complexity
If data is stored in a single large database, then storage management is simplified, but data grooming and removal operations become more complex
Solution Approach 1:
By organizing data into separate container instances for each tenant, the patent enables independent grooming and removal operations on each container without affecting the entire database system. This segmentation makes data maintenance operations simpler and more targeted compared to managing a single large monolithic database.
Data Source
AI summary
Techniques are disclosed relating to storage of network event information for multiple tenants. In some embodiments, one or more host computer systems are configured to maintain a plurality of containers operable to isolate network event information of a plurality of tenants from others of the plurality of tenants. The plurality of containers includes a first container that includes a first database executable to store network event information for a first of the plurality of tenants, and a second container that includes a second database executable to store network event information for a second of the plurality of tenants. In some embodiments, a management computer system is configured to receive, from the first tenant, a request to access network event information of the first tenant and route the request to a host computer system maintaining the first container to cause the first database to service the request.


