Multi-tenant SaaS Platform Service Discovery and Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current business application platforms are either single-tenanted, leading to high deployment and maintenance costs, or multi-tenanted, which complicates management due to varying client schemas and security, traffic, and reliability concerns, while also being inefficient in resource utilization.

Innovation Solution

An extensible multi-tenant software-as-a-service model with a discovery service that enables clients to access organization services hosted in scalable clusters, allowing seamless access and automatic location updates for uninterrupted service, using a trusted third-party authentication service and dynamic APIs for secure and efficient management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a single-tenanted platform is used, then security and reliability are improved, but deployment cost and maintenance cost increase significantly

Engineering Contradiction:
Improveplatform securityVSAvoiddeployment and maintenance cost
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent merges multiple tenant environments into a single shared platform infrastructure, where multiple organizations run their applications on common hardware and software resources. This consolidation reduces the need for separate dedicated platforms for each tenant, thereby lowering deployment and maintenance costs while maintaining security through virtualization and isolation mechanisms.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The platform is designed to serve multiple tenants simultaneously with a single infrastructure, making the system universal in its functionality. The same platform resources (computing, storage, networking) are shared across multiple organizations, each with their own isolated environments,从而实现 cost-effective multi-tenancy while preserving security boundaries.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Productivity

If a multi-tenant system is implemented, then resource utilization is improved, but management complexity increases due to varying client schemas and security requirements

Engineering Contradiction:
Improveresource utilizationVSAvoidsystem management complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent segments the multi-tenant system into distinct virtualized environments for each tenant, allowing independent schema designs and security configurations. Each tenant operates in an isolated namespace with their own data models and access controls, while sharing the underlying physical infrastructure. This segmentation reduces management complexity by enabling independent configuration and administration of each tenant environment.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system introduces intermediary components such as virtualization layers, service meshes, and centralized management APIs that mediate between diverse tenant requirements and the shared infrastructure. These intermediaries abstract the complexity of managing varying schemas and security policies, providing standardized interfaces for resource allocation, access control, and monitoring across all tenants.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If location changes in organization services are implemented, then service availability is improved, but client access stability may be affected

Engineering Contradiction:
Improveservice availabilityVSAvoidclient access stability
Core Design Contradiction:
ReliabilityVSStability of the object's composition

Solution Approach 1:

The system implements feedback mechanisms where the platform continuously monitors service location changes and automatically notifies clients through event subscriptions or polling mechanisms. When organization services move locations, the system detects these changes and propagates updated endpoint information to clients, ensuring seamless access continuity without requiring client-side manual updates.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system performs preliminary actions by pre-configuring service location registration and discovery mechanisms before actual service migrations occur. Clients are set up with service location subscription capabilities in advance, so when location changes happen, the clients can automatically receive and apply updated location information without interruption to their access patterns.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP2156308B1Extensible and programmable multi-tenant service architecture
Publication Date: 2018.11.07 MICROSOFT TECHNOLOGY LICENSING LLC
  • EP2156308B1 patent drawingFigure 1
  • EP2156308B1 patent drawingFigure 2
  • EP2156308B1 patent drawingFigure 3

AI summary

An extensible, multi-tenant software-as-a-service business application platform is provided for hosting multiple organizations. Organization services are provided by virtual or physical servers with dedicated data stores assembled in scalable groups. Distributed interaction between components of the scalable groups may enable extensibility and reliability, while changes in locations of organization services are provided to the client(s) for seamless continuation of the client's access to the services. Customizable and dynamic APIs for accessing each organization's data and applications isolated from the others and pluggable third party authentication services may also be integrated into the platform.