Pre-Readied Trust Boundary Components for Low-Latency Multi-Tenancy

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In multi-tenancy environments, especially in public cloud computing, there is a need to protect against potential hostility between tenants while maintaining low latency and efficient resource utilization, as traditional virtual machines require significant boot time and may lead to resource contention.

Innovation Solution

A pool of pre-readied trust boundary components, such as virtual machines, are maintained to quickly start up and manage resource containers, with a container management agent ensuring efficient resource allocation and affinity, reducing resource contention and enabling fast startup of trust boundaries for secure and efficient processing.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional virtual machines are used to provide trust boundaries in multi-tenancy environments, then security against hostile tenants is improved, but startup time increases significantly

Engineering Contradiction:
ImprovesecurityVSAvoidstartup time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent pre-creates and maintains a pool of trust boundary components (virtual machines) in a ready state before they are needed. These pre-configured VMs can be quickly activated and assigned to tenants, avoiding the lengthy boot process of traditional VM creation while maintaining security boundaries.

Inventive Principle:
Principle #10Preliminary action

2Speed

If trust boundary components are pre-readied to reduce startup latency, then startup speed is improved, but resource utilization may worsen due to maintaining idle components

Engineering Contradiction:
Improvestartup speedVSAvoidresource utilization
Core Design Contradiction:
SpeedVSUse of energy by moving object

Solution Approach 1:

Multiple trust boundary components are consolidated into a single physical or virtual infrastructure pool. The system dynamically allocates and de-allocates these pre-configured components to different tenants based on demand, reducing the total number of physical resources needed while maintaining fast startup capability.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system dynamically manages the pool of pre-readied trust boundary components, adjusting their state and allocation based on current tenant demands. Components can be activated, deactivated, and re-purposed dynamically, optimizing resource utilization while maintaining startup speed.

Inventive Principle:
Principle #15Dynamics

3Productivity

If multiple tenants share common physical resources in a multi-tenancy environment, then resource efficiency is improved, but security against hostile actions between tenants deteriorates

Engineering Contradiction:
Improveresource efficiencyVSAvoidsecurity
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent introduces trust boundary components (virtual machines) that segment and isolate tenant workloads from each other while sharing underlying physical infrastructure. Each tenant operates within their own trusted boundary, preventing hostile actions from affecting other tenants while maintaining resource efficiency through shared physical resources.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentEP3356983B1Multi-tenant environment using pre-readied trust boundary components
Publication Date: 2019.10.30 MICROSOFT TECHNOLOGY LICENSING LLC
  • EP3356983B1 patent drawingFigure 1
  • EP3356983B1 patent drawingFigure 2
  • EP3356983B1 patent drawingFigure 3~4

AI summary

The low latency use of a multi-tenancy environment. To protect against hostility between tenants within different trust domains, tenant(s) of a common trust domain are run within a trust boundary component. Thus, there is security to protect against potential hostility between tenants of different trust domains. In order to quickly start up trust boundary components, there are multiple pre-readied (e.g., initialized, pre-booted, and/or snapshotted) trust boundary components that may be started up quickly when a new trust boundary is to be established. Processes within the trust boundary component may additionally be run within a resource container that facilitates allocation of resources amongst the various processes. Because trust boundary components may be started up quickly, the multi-tenancy environment may have security (as provided by the trust boundary components) while still being lower latency (due to the fast availability of pre-readied trust boundaries).