Nested Multi-Tenancy Data Protection Hierarchy

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current multi-tenant computer systems face challenges in securely and efficiently managing access to shared infrastructure services across multiple tenants with varying levels of data protection scopes, leading to complexity in data access and privacy issues.

Innovation Solution

Implementing a nested multi-tenancy model with a data protection scope hierarchy that allows for scalable provisioning of data protection scopes, enabling secure access to shared infrastructure services by treating cloud products and service products as first-class tenants with subordinate subtenants, and using cryptographic tokens to authenticate and authorize access requests.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a traditional multi-tenant system manages access to shared infrastructure services, then multiple tenants can access services, but data access complexity and privacy issues increase due to varying data protection scopes

Engineering Contradiction:
Improvedata protection scope managementVSAvoidaccess management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements a nested tenancy model where tenants can have subtenants, creating a hierarchical structure. This nesting allows different levels of data protection scopes to be organized in a tree-like hierarchy, where each level can define its own access policies while inheriting from parent levels, thereby managing complexity through structured organization rather than flat, monolithic access control

Inventive Principle:
Principle #7Nested doll (Nesting)

Solution Approach 2:

The patent segments the multi-tenant system into hierarchical levels with distinct data protection scopes. Each tenant and subtenant operates at a specific level with defined access boundaries, allowing the system to divide complex access management into manageable segments rather than handling all tenant interactions at a single level

Inventive Principle:
Principle #1Segmentation

2Reliability

If a nested tenancy model with hierarchy is implemented, then data access complexity is reduced and security is improved, but system structure becomes more complex

Engineering Contradiction:
Improvedata securityVSAvoidsystem structure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The hierarchical nesting structure organizes tenants and subtenants in levels, where each level enforces its own security policies. This nesting improves reliability by ensuring that data access is controlled at multiple hierarchical boundaries, with each level validating access independently, creating layered security that enhances protection while maintaining a structured, manageable system architecture

Inventive Principle:
Principle #7Nested doll (Nesting)

3Reliability

If cryptographic tokens are used for authentication and authorization, then access security is enhanced, but authentication overhead increases

Engineering Contradiction:
Improveaccess authentication securityVSAvoidauthentication processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary authentication actions by establishing cryptographic token relationships in advance within the hierarchical structure. Tokens are issued and validated at each hierarchical level before actual data access operations, allowing the system to pre-establish trust relationships and access permissions, thereby reducing authentication overhead during actual data operations

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11695559B2Nested tenancy that permits a hierarchy having a plurality of levels
Publication Date: 2023.07.04 SALESFORCE INC
  • US11695559B2 patent drawing
  • US11695559B2 patent drawing
  • US11695559B2 patent drawing

AI summary

A multi-tenant computer system implements a platform for providing data protection scopes to shared infrastructure services according to a nested tenant model that permits a hierarchy having a plurality of levels. The multi-tenant computer system provisions data protection scopes for cloud products, service products, cloud product tenants, service products operating in the context of cloud products, service products operating in the context of cloud product tenants, and combinations of the foregoing.