Partition-Scoped Diagnostic Framework for Multitenant Server Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In multitenant application server environments, existing monitoring and diagnostics systems lack effective partition-level visibility and security, leading to potential data access issues and operational inefficiencies, as system administrators have broad access while partition administrators are restricted from necessary information.

Innovation Solution

A system and method that incorporates a diagnostic framework, such as the WebLogic Diagnostic Framework (WLDF), which enables partition scoped logging, monitoring, and diagnostic imaging, allowing for secure access to partition-specific data through log file identifiers, diagnostic image capture modules, and partition monitoring modules, ensuring that only authorized administrators can access relevant information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If system administrators have broad access to monitoring and diagnostic information, then operational visibility and system management capability are improved, but security and data isolation between tenants deteriorate

Engineering Contradiction:
Improvesystem management capabilityVSAvoiddata access security risks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent implements partition-level segmentation of monitoring and diagnostic data, where each partition (representing a tenant) has its own isolated data structures, log files, and diagnostic information. This allows system administrators to access information at the domain level while partition administrators maintain security and isolation at the tenant level, resolving the contradiction between broad access and data security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies local quality by providing partition-specific monitoring and diagnostic capabilities tailored to each tenant's needs. Each partition receives customized logging, monitoring, and diagnostic imaging based on its specific configuration and requirements, while maintaining security boundaries. This enables appropriate access levels for different administrative roles without compromising overall system security.

Inventive Principle:
Principle #3Local quality

2Object-affected harmful factors

If partition administrators are restricted from accessing certain information, then data isolation and security are improved, but operational visibility and diagnostic capability deteriorate

Engineering Contradiction:
Improvedata isolation securityVSAvoidpartition-specific diagnostic information
Core Design Contradiction:
Object-affected harmful factorsVSLoss of information

Solution Approach 1:

The patent segments diagnostic information into partition-specific data structures that are accessible only to authorized partition administrators. Each partition maintains its own isolated diagnostic data, log files, and monitoring information, ensuring security while providing necessary operational visibility to the appropriate administrators through controlled access mechanisms.

Inventive Principle:
Principle #1Segmentation

3Device complexity

If a unified monitoring system is implemented across the entire domain, then system complexity is reduced, but partition-level visibility and security control increase

Engineering Contradiction:
Improvemonitoring system structureVSAvoidpartition-level security control
Core Design Contradiction:
Device complexityVSObject-affected harmful factors

Solution Approach 1:

The patent implements a unified monitoring framework that is segmented into domain-level and partition-level components. The domain-level system provides centralized management and overview, while partition-level components maintain security controls and isolated diagnostic capabilities. This segmentation allows the system to achieve both unified management and partition-specific security without excessive complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates a universal monitoring framework that serves multiple functions: domain-wide system management, partition-level security control, partition-specific diagnostic imaging, and log management. This multi-functional approach consolidates what would otherwise require separate systems into a single unified framework, reducing overall complexity while maintaining security.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9959421B2System and method for monitoring and diagnostics in a multitenant application server environment
Publication Date: 2018.05.01 ORACLE INT CORP
  • US9959421B2 patent drawing
  • US9959421B2 patent drawing
  • US9959421B2 patent drawing

AI summary

A system and method for monitoring and diagnostics in an application server environment. A system can comprise one or more computers, which can include an application server environment executing thereon, together with a plurality of deployable resources configured to be used within the application server environment, and a plurality of partitions, wherein each partition provides an administrative and runtime subdivision of a domain. A diagnostic framework, such as a WebLogic Diagnostic Framework (WLDF) can also be provided, wherein the diagnostic framework is configured to perform at least one action from the group consisting of partition scoped logging, partition scoped monitoring, and partition scoped diagnostic imaging.