Per-Tenant Middleware Policy Enforcement in Cloud Hosts

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In multi-tenant cloud computing environments, existing technologies face challenges in managing and enforcing per-tenant middleware policies across multiple tenants, leading to inefficiencies in network traffic management and security.

Innovation Solution

A system comprising multiple hosts running virtual machines, with a middleware management service that applies per-tenant middleware policies by directing network traffic to a middleware enforcement mechanism, ensuring that each tenant's policy is enforced based on their identity, allowing for flexible and secure management of network traffic.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If per-tenant middleware policies are enforced for each tenant in a multi-tenant cloud environment, then security and customization are improved, but system complexity and overhead increase

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the multi-tenant system into distinct components: a middleware management service that maintains per-tenant policies, a service coordination system that directs traffic, and middleware enforcement mechanisms at individual hosts. This segmentation allows security policies to be customized per tenant while distributing the enforcement burden across multiple independent components, preventing centralized complexity from becoming unmanageable.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The service coordination system acts as an intermediary between network traffic and the middleware enforcement mechanisms. It receives network traffic, determines the appropriate tenant and middleware policy, and directs traffic to the correct enforcement mechanism. This intermediary layer simplifies the overall system architecture by centralizing the decision-making logic while keeping enforcement distributed.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If per-tenant middleware policies are enforced for each tenant, then customization and security are improved, but network traffic management overhead increases

Engineering Contradiction:
ImprovecustomizationVSAvoidtraffic management overhead
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The middleware management service maintains pre-configured middleware policies for each tenant before network traffic arrives. These policies are established in advance based on tenant identity and security requirements, allowing the service coordination system to quickly match incoming traffic with appropriate pre-defined policies without performing complex real-time analysis, thereby reducing traffic management overhead.

Inventive Principle:
Principle #10Preliminary action

3Productivity

If middleware enforcement is distributed across multiple hosts, then scalability is improved, but coordination complexity increases

Engineering Contradiction:
ImprovescalabilityVSAvoidcoordination complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The service coordination system performs multiple functions: it receives network traffic, identifies the target tenant, selects the appropriate middleware policy, determines the correct host and virtual machine, and directs traffic to the appropriate middleware enforcement mechanism. This multi-functional approach consolidates coordination logic in a single component, allowing the system to scale by adding hosts without proportionally increasing coordination complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10924404B2Multi-tenant middleware cloud service technology
Publication Date: 2021.02.16 MICROSOFT TECHNOLOGY LICENSING LLC
  • US10924404B2 patent drawing
  • US10924404B2 patent drawing
  • US10924404B2 patent drawing

AI summary

A system that includes multiple hosts, each running a plurality of virtual machines. The system may be, for example, a cloud computing environment in which there are services and a service coordination system that communicates with the hosts and with the services. The services include a middleware management service that is configured to maintain per-tenant middleware policy for each of multiple tenants. The middleware management service causes the middleware policy to be applied to network traffic by directing network traffic to a middleware enforcement mechanism. This middleware policy is per-tenant in that it depends on an identity of a tenant.