Multi-Tenant Job Management with Subnetwork Access Isolation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing job management services in cloud environments face challenges in ensuring high reliability and security while maintaining cost-effectiveness, particularly in multi-tenant configurations, where the manipulation of multiple tenants is complex and resource allocation is inefficient.
Innovation Solution
A system is implemented where one resource is divided into subnetworks for each tenant, with individual access restrictions and job management functions allocated to each subnetwork, allowing for secure and efficient use of shared resources among multiple tenants.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a single-tenant configuration is used to ensure security and isolation, then security and reliability are improved, but resource utilization deteriorates and operational costs increase
Solution Approach 1:
The patent segments the network into multiple virtual networks (VPCs) that are logically isolated but physically shared. Each tenant is assigned to a specific VPC, creating segmentation that ensures security and isolation while allowing multiple tenants to share the same physical infrastructure, thus improving resource utilization compared to single-tenant configurations.
Solution Approach 2:
The patent introduces a virtualization dimension by creating virtual networks atop physical network infrastructure. This dimensional transformation allows the system to provide both the isolation of single-tenant configurations and the resource efficiency of multi-tenant configurations simultaneously, resolving the contradiction between security and resource utilization.
2Productivity
If a multi-tenant configuration is used to improve resource utilization and reduce costs, then resource efficiency is improved, but security and access control deteriorate
Solution Approach 1:
The patent segments the multi-tenant environment into isolated virtual networks, where each tenant operates in their own VPC. This segmentation maintains security boundaries while allowing efficient resource sharing across tenants, thus improving security posture in multi-tenant configurations without sacrificing resource utilization.
Solution Approach 2:
The patent introduces virtual network components (vswitches, gateways, firewalls) as intermediaries between tenants and shared resources. These intermediary elements enforce access control policies and security rules, enabling secure multi-tenant operations while maintaining high resource utilization through shared infrastructure.
3Reliability
If individual resources are allocated to each tenant in a single-tenant configuration, then security is improved, but operational costs increase due to duplicate resource allocation
Solution Approach 1:
The patent merges multiple single-tenant resources into shared physical infrastructure that is logically divided into separate virtual networks. This consolidation eliminates duplicate physical resource allocation while maintaining the security isolation of single-tenant configurations through virtualization, thus reducing operational costs without compromising security.
Solution Approach 2:
The patent makes physical network resources universal by designing them to serve multiple tenants simultaneously through virtualization. The same physical switches, routers, and servers can be shared across multiple VPCs and tenants, enabling one resource to perform multiple functions for different tenants, thereby reducing the total quantity of resources needed and lowering operational costs.
4Quantity of substance
If a multi-tenant configuration is used to reduce costs, then operational cost is improved, but the manipulation and management of multiple tenants becomes complex
Solution Approach 1:
The patent introduces a network management system as an intermediary that automates the provisioning, configuration, and management of virtual networks and tenant assignments. This intermediary simplifies the complex tasks of managing multiple tenants by providing centralized control and automation, thus improving ease of operation in multi-tenant configurations while maintaining cost efficiency.
Solution Approach 2:
The patent implements self-service capabilities that allow tenants to independently manage their own virtual network configurations, resource allocations, and access policies through automated interfaces. This self-service approach reduces the operational complexity of managing multiple tenants by enabling autonomous tenant management, thereby improving ease of operation while maintaining cost-effective multi-tenant operations.
Data Source
AI summary
A non-transitory computer-readable recording medium stores therein a program that causes a computer to execute a process including, in one resource that provides a job management service using a specific network, the resource having a plurality of tenants set therein, each of the tenants having a plurality of functions for performing job management set therein, each of the functions being allocated with a different subnetwork of the specific network, performing individual access restriction for each of the functions based on the subnetwork, and performing individual job management for each of the tenants using a shared function of the plurality of tenants in the job management provided in a commonly used portion of the plurality of tenants of the resource and the functions set for each of the tenants.


