Per-Tenant Isolation Layer for Multi-Tenant Cloud Systems

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing multi-tenant database systems face challenges in applying effective and efficient isolation features on a per-tenant basis, leading to cumbersome and costly deployments due to blanket condition parameters at the environmental level, which can result in failed outbound requests and incorrect feature visibility for end-users.

Innovation Solution

Implementing pre-configured per-tenant isolation by creating isolation groups with defined requirements, using call-out functions, and applying an isolation layer on top of a base layer to generate a unique variant of the platform software, allowing for per-tenant distinctions and flexible deployment of isolation features without impacting the base version of the customer organization.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If blanket condition parameters are applied at the environmental level for isolation, then isolation coverage is improved, but system complexity and deployment cost increase

Engineering Contradiction:
Improveisolation coverageVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments isolation requirements into tenant-specific configurations rather than applying blanket environmental-level parameters. Each tenant can have customized isolation settings, allowing precise control without system-wide complexity. The system divides isolation logic into modular tenant-level policies that can be independently managed.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies local quality by enabling different isolation characteristics for different tenants within the same multi-tenant environment. Instead of uniform environmental-level isolation, each tenant receives tailored isolation parameters suited to their specific needs, achieving effective isolation without imposing system-wide complexity.

Inventive Principle:
Principle #3Local quality

2Reliability

If blanket condition parameters are applied at the environmental level for isolation, then isolation enforcement is improved, but ease of operation deteriorates

Engineering Contradiction:
Improveisolation enforcementVSAvoidease of operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent segments isolation enforcement into tenant-specific manageable units. Each tenant's isolation requirements are configured independently, making operations simpler and more intuitive. Administrators can manage isolation settings for individual tenants without dealing with complex system-wide conditional parameters.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements preliminary action by providing pre-configured isolation templates and automated tenant provisioning. Isolation settings are established in advance through standardized processes, eliminating the need for complex manual configuration and improving ease of operation while maintaining enforcement integrity.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If isolation is applied at the end-user stage of deployment, then isolation effectiveness is improved, but deployment cost and time increase

Engineering Contradiction:
Improveisolation effectivenessVSAvoiddeployment time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies preliminary action by pre-configuring isolation requirements during tenant provisioning and platform setup. Isolation policies are established before end-user deployment, ensuring effectiveness from the outset without requiring time-consuming post-deployment adjustments or fixes.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent segments the deployment process into isolated tenant-specific configurations that can be independently provisioned and validated. This modular approach allows parallel processing of multiple tenants' isolation setups, reducing overall deployment time while maintaining effectiveness.

Inventive Principle:
Principle #1Segmentation

4Reliability

If blanket condition parameters are used for isolation, then comprehensive coverage is improved, but adaptability to per-tenant needs deteriorates

Engineering Contradiction:
Improvecomprehensive coverageVSAvoidper-tenant flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments isolation coverage into tenant-specific configurable parameters. Each tenant can have customized isolation settings that comprehensively address their specific requirements while maintaining overall system-wide coverage. This modular segmentation enables both comprehensive coverage and per-tenant adaptability simultaneously.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements dynamics by making isolation parameters adaptive and configurable at the tenant level. Isolation settings can be dynamically adjusted for each tenant based on their specific needs, allowing the system to maintain comprehensive coverage while adapting to varying per-tenant requirements.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS20240187418A1Systems, methods, and apparatuses for pre-configured per-tenant isolation in a multi-tenant cloud based computing environment
Publication Date: 2024.06.06 SALESFORCE INC
  • US20240187418A1 patent drawing
  • US20240187418A1 patent drawing
  • US20240187418A1 patent drawing

AI summary

An exemplary system having a processor and a memory therein includes means for creating an isolation group, in which creating the isolation groups includes: defining isolation requirements, identifying a group of features utilizing call-out functions, and selecting from among the group of features utilizing call-out functions a group of features having the defined isolation requirements; deploying platform software integrating the isolation requirements, in which the platform software contains instructions to map the isolation requirements to a customer organization; creating the customer organization; creating a unique variant of the customer organization, in which creating the unique variant of the customer organization includes declaratively applying an isolation layer containing isolation requirements on top of a base layer for the customer organization; and deploying the unique variant of the customer organization onto the customer organization's computing infrastructure, in which the unique variant validates per-tenant distinctions for various applications subjected to the isolation requirements.