Multitenant Analytics Security Intermediary Layer
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Multitenant database systems face challenges in ensuring data security when performing analytics across tenant data, as existing security schemes are not effectively applied to users associated with different tenants, leading to potential unauthorized access and data breaches.
Innovation Solution
A system that includes an input interface to receive requests for analytics data, a processor to determine security levels based on commingled data, and a memory to manage permissions, ensuring that only credentialed users with sufficient security clearance can access analytics data, with an option for security escalation or reduction based on tenant preferences.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If data security is applied to users in multitenant data analysis system associated with tenants not under the original security scheme, then data security is improved, but device complexity increases
Solution Approach 1:
The patent introduces a security intermediary layer that sits between the multitenant data analysis system and the data storage. This intermediary component evaluates security credentials, determines access permissions, and mediates data access requests without requiring changes to the underlying security schemes of individual tenants. The intermediary acts as a broker that translates between different security models and enforces unified security policies.
Solution Approach 2:
The security system is segmented into distinct functional components: credential evaluation modules, permission determination modules, and access control modules. Each segment handles a specific aspect of security enforcement, allowing the system to manage complex security requirements through modular, independently manageable components rather than a monolithic security scheme.
2Reliability
If security levels are determined for commingled data used in analytics, then data security is improved, but loss of information increases
Solution Approach 1:
The patent applies local quality by determining security levels on a per-data-instance basis rather than applying a uniform security policy to all commingled data. Each data instance retains its original security characteristics and access requirements, allowing the system to preserve fine-grained security distinctions while enabling analytics on appropriately authorized data subsets.
Solution Approach 2:
The system performs partial action by allowing analytics to proceed on subsets of commingled data for which the user has sufficient credentials, rather than blocking all analytics operations. The security evaluation selectively permits access to portions of the data that meet security requirements while excluding portions that don't, maintaining productivity without compromising security.
Data Source
AI summary
A system for analytics security includes processor(s) and a readable medium. The readable medium causes the system to perform operations comprising receiving a request for analytics data; determining the analytics data based on the request (the analytics data comprises result(s) of an analytic calculation performed on commingled data and the commingled data comprises tenant data shared by a tenant and other tenant data shared by other tenant(s)); determining security information associated with the analytics data (the security information associated with the analytics data is based on the commingled data used for determining the analytics data); determining permissions associated with the requestor based on the tenant; determining whether the requestor is credentialed based on the security information associated with the analytics data and the permissions associated with the requestor; and providing the analytics data to the requestor based on a determination that the requestor is credentialed.


