PEaaS Interface for Asynchronous Policy Enforcement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Multi-tenant database systems face service disruptions due to users consuming excessive resources, leading to system overload and degradation, as existing solutions lack effective mechanisms to enforce resource protection policies across distributed platforms.

Innovation Solution

The implementation of Policy Enforcement as a Service (PEaaS) tracks user infractions and issues suspensions based on customer-defined policies, utilizing a PEaaS interface to monitor usage metrics and enforce resource restrictions across distributed systems, preventing overload and ensuring service availability.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If users are allowed to access shared database resources freely, then system usability and accessibility are improved, but service disruptions and system overload occur due to excessive resource consumption

Engineering Contradiction:
Improveaccessibility to database resourcesVSAvoidservice availability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a policy enforcement service (PEaaS) as an intermediary layer between users and the shared database system. This service monitors resource consumption, enforces usage policies, and manages user suspensions automatically, thereby protecting service availability while maintaining ease of access for legitimate users.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements continuous monitoring of resource consumption metrics and provides feedback through policy enforcement. When threshold violations are detected, the system automatically suspends offending users and notifies them of policy violations, creating a closed-loop control mechanism that prevents service disruption while maintaining open access.

Inventive Principle:
Principle #23Feedback

2Reliability

If resource consumption monitoring and user suspension mechanisms are implemented, then service reliability is improved, but system complexity increases due to additional enforcement infrastructure

Engineering Contradiction:
Improveservice availabilityVSAvoidsystem architecture complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The policy enforcement service is designed as a universal, multi-functional component that handles monitoring, policy evaluation, user suspension, and notification within a single integrated system. This consolidates multiple functions into one service, reducing overall system complexity while maintaining high reliability through centralized policy management.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Measurement precision

If real-time monitoring of usage metrics is performed, then detection precision of resource abuse is improved, but processing overhead and system performance degradation occur

Engineering Contradiction:
Improvedetection accuracy of resource abuseVSAvoidsystem processing efficiency
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The system implements partial monitoring by focusing only on critical resource metrics and threshold-based detection rather than comprehensive real-time analysis of all user activities. This selective monitoring approach maintains high detection precision for policy violations while minimizing processing overhead and preserving system productivity.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS10778543B2Opaque interface for enclosed/wrapped asynchronous pushing and/or pulling data between policy enforcement as a service (PEaaS) components
Publication Date: 2020.09.15 SALESFORCE INC
  • US10778543B2 patent drawing
  • US10778543B2 patent drawing
  • US10778543B2 patent drawing

AI summary

Systems, methods, and computer-readable media for providing a Policy Enforcement as a Service (PEaaS) are described. A processing device may collect set(s) of policy parameter values from one or more third party platforms, respectively, by communication with remote interface(s) employed on the one or more third party platforms, respectively; each set of policy parameter values defines a threshold for issuing a user suspension for a service provided by a respective one of the third party platforms; collect one or more sets of usage metrics for the one or more services from the one or more third party platforms, respectively, by communication with the remote interface(s); the communication with the remote interface(s) to collect the sets of usage metric(s) is asynchronous with communications by which the remote interface(s) received the usage metrics. Other embodiments may be described and/or claimed.