Partitioned Connector Scope Management in Multitenant Servers

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing application server environments face challenges in supporting connectors and resource adapters in a multitenant setup, where resources and applications need to be isolated and managed efficiently across partitions, while ensuring security and administrative isolation between tenants.

Innovation Solution

The system provides a method for deploying and managing connectors and resource adapters within a multitenant application server environment by using partitions as administrative and runtime subdivisions, with a connector container determining the partition scope of deployed resource adapters to ensure isolation and access control, and utilizing resource group templates to configure and deploy resources specific to each partition.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If connectors and resource adapters are deployed in a multitenant application server environment, then resource sharing and scalability are improved, but resource isolation and security between tenants deteriorate

Engineering Contradiction:
Improveresource sharingVSAvoidresource isolation
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces partitions as administrative and runtime subdivisions of the domain, creating isolated environments for different tenants. Each partition can have its own resource adapters and connectors, enabling resource sharing at the domain level while maintaining isolation at the partition level. This segmentation resolves the contradiction by allowing multiple tenants to share the same application server infrastructure without compromising security or resource isolation.

Inventive Principle:
Principle #1Segmentation

2Reliability

If partition-level resource adapters are deployed to ensure tenant isolation, then security and isolation are improved, but device complexity and management overhead deteriorate

Engineering Contradiction:
Improvetenant isolationVSAvoidmanagement overhead
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal connector container that handles both domain-level and partition-level resource adapters through a unified mechanism. The connector container determines the scope (domain or partition) of resource adapters and manages them accordingly, eliminating the need for separate management mechanisms for different scopes. This multi-functionality reduces management overhead while maintaining secure tenant isolation through partition-level resource adapters.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Adaptability or versatility

If domain-level resource adapters are used for shared resources, then adaptability and resource sharing are improved, but tenant-specific access control and isolation deteriorate

Engineering Contradiction:
Improveresource sharingVSAvoidaccess control
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent segments resource adapter management into two levels: domain-level for shared resources and partition-level for tenant-specific resources. The connector container automatically determines the scope of each resource adapter and enforces access control accordingly. This segmentation allows domain-level resource adapters to provide shared functionality while partition-level resource adapters ensure tenant-specific access control, resolving the contradiction between resource sharing and access control.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS10193754B2System and method for supporting connectors in a multitenant application server environment
Publication Date: 2019.01.29 ORACLE INT CORP
  • US10193754B2 patent drawing
  • US10193754B2 patent drawing
  • US10193754B2 patent drawing

AI summary

In accordance with an embodiment, described herein is a system and method for supporting the use of connectors in an application server environment. The method can provide, a plurality of deployable resources which can be used within the application server environment, and one or more partitions, wherein each partition provides an administrative and runtime subdivision of the domain. The methods and systems can associate one or more deployed partition-level resource adapters to the one or more partitions, each of the one or more deployed partition-level resource adapters associated with one of the one or more partitions. Finally, the methods and systems can determine, by a connector container, a partition scope of one of the one or more deployed partition-level resource adapters.