Multi-Tenant Job Management with Subnetwork Access Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing job management services in cloud environments face challenges in ensuring high reliability and security while maintaining cost-effectiveness, particularly in multi-tenant configurations, where the manipulation of multiple tenants is complex and resource allocation is inefficient.

Innovation Solution

A system is implemented where one resource is divided into subnetworks for each tenant, with individual access restrictions and job management functions allocated to each subnetwork, allowing for secure and efficient use of shared resources among multiple tenants.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a single-tenant configuration is used to ensure security and isolation, then security and reliability are improved, but resource utilization deteriorates and operational costs increase

Engineering Contradiction:
ImprovesecurityVSAvoidresource utilization
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent segments the network into multiple virtual networks (VPCs) that are logically isolated but physically shared. Each tenant is assigned to a specific VPC, creating segmentation that ensures security and isolation while allowing multiple tenants to share the same physical infrastructure, thus improving resource utilization compared to single-tenant configurations.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a virtualization dimension by creating virtual networks atop physical network infrastructure. This dimensional transformation allows the system to provide both the isolation of single-tenant configurations and the resource efficiency of multi-tenant configurations simultaneously, resolving the contradiction between security and resource utilization.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Productivity

If a multi-tenant configuration is used to improve resource utilization and reduce costs, then resource efficiency is improved, but security and access control deteriorate

Engineering Contradiction:
Improveresource utilizationVSAvoidsecurity
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent segments the multi-tenant environment into isolated virtual networks, where each tenant operates in their own VPC. This segmentation maintains security boundaries while allowing efficient resource sharing across tenants, thus improving security posture in multi-tenant configurations without sacrificing resource utilization.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces virtual network components (vswitches, gateways, firewalls) as intermediaries between tenants and shared resources. These intermediary elements enforce access control policies and security rules, enabling secure multi-tenant operations while maintaining high resource utilization through shared infrastructure.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If individual resources are allocated to each tenant in a single-tenant configuration, then security is improved, but operational costs increase due to duplicate resource allocation

Engineering Contradiction:
ImprovesecurityVSAvoidoperational cost
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent merges multiple single-tenant resources into shared physical infrastructure that is logically divided into separate virtual networks. This consolidation eliminates duplicate physical resource allocation while maintaining the security isolation of single-tenant configurations through virtualization, thus reducing operational costs without compromising security.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent makes physical network resources universal by designing them to serve multiple tenants simultaneously through virtualization. The same physical switches, routers, and servers can be shared across multiple VPCs and tenants, enabling one resource to perform multiple functions for different tenants, thereby reducing the total quantity of resources needed and lowering operational costs.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Quantity of substance

If a multi-tenant configuration is used to reduce costs, then operational cost is improved, but the manipulation and management of multiple tenants becomes complex

Engineering Contradiction:
Improveoperational costVSAvoidtenant management
Core Design Contradiction:
Quantity of substanceVSEase of operation

Solution Approach 1:

The patent introduces a network management system as an intermediary that automates the provisioning, configuration, and management of virtual networks and tenant assignments. This intermediary simplifies the complex tasks of managing multiple tenants by providing centralized control and automation, thus improving ease of operation in multi-tenant configurations while maintaining cost efficiency.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements self-service capabilities that allow tenants to independently manage their own virtual network configurations, resource allocations, and access policies through automated interfaces. This self-service approach reduces the operational complexity of managing multiple tenants by enabling autonomous tenant management, thereby improving ease of operation while maintaining cost-effective multi-tenant operations.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS20260017097A1Computer-readable recording medium, service providing method, and service providing apparatus
Publication Date: 2026.01.15 FUJITSU LTD
  • US20260017097A1 patent drawing
  • US20260017097A1 patent drawing
  • US20260017097A1 patent drawing

AI summary

A non-transitory computer-readable recording medium stores therein a program that causes a computer to execute a process including, in one resource that provides a job management service using a specific network, the resource having a plurality of tenants set therein, each of the tenants having a plurality of functions for performing job management set therein, each of the functions being allocated with a different subnetwork of the specific network, performing individual access restriction for each of the functions based on the subnetwork, and performing individual job management for each of the tenants using a shared function of the plurality of tenants in the job management provided in a commonly used portion of the plurality of tenants of the resource and the functions set for each of the tenants.