Extensible SaaS Platform with Virtualized Tenant Isolation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current Software as a Service (SaaS) architectures face challenges in customization and security, as they provide a centralized management model that may not cater to diverse customer needs and can compromise security when applications and data are exposed over the internet, lacking effective content protection and privacy guarantees.
Innovation Solution
An extensible SaaS platform is developed that supports the design and deployment of multiple web services, offering a virtual private internet environment through selective security and privacy services, enabling customization and secure multi-tenant service delivery by integrating security, privacy, and administrative services into the service execution pipeline.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If centralized management model is used in SaaS architecture, then scalability and cost-effectiveness are improved, but security and customization capabilities deteriorate
Solution Approach 1:
The patent segments the SaaS architecture into multiple virtualized tenants, each operating in isolated virtual environments. This segmentation allows centralized infrastructure management while providing customized security policies and data isolation for each tenant, resolving the contradiction between scalability and security.
Solution Approach 2:
The patent introduces virtualization technology as an intermediary layer between the centralized infrastructure and individual tenants. This intermediary enables centralized resource management while providing customized security controls, privacy protection, and isolation for each tenant, thus maintaining both scalability and security.
2Ease of operation
If applications are exposed over the internet for SaaS delivery, then accessibility and service delivery are improved, but content protection and privacy guarantees deteriorate
Solution Approach 1:
The patent implements virtualization as a protective shell around tenant data and applications. This virtualized environment acts as a flexible barrier that maintains internet accessibility while providing strong content protection and privacy guarantees through isolation and controlled access mechanisms.
Solution Approach 2:
The patent creates an inert virtualized environment for each tenant that isolates their data and applications from external threats. This controlled environment maintains accessibility over the internet while protecting content through virtualization-based isolation and security policies.
3Productivity
If multi-tenant architecture is used to host multiple applications, then resource utilization and cost-effectiveness are improved, but security isolation and customization capabilities deteriorate
Solution Approach 1:
The patent implements dynamic virtualization that allows the multi-tenant system to adapt to different customer needs. Each tenant can have customized security policies, data models, and application configurations within their virtual environment, while still sharing the underlying infrastructure, thus maintaining both resource utilization and customization.
4Ease of manufacture
If centralized feature updating is implemented in SaaS, then maintenance efficiency is improved, but customer-specific customization and security control deteriorate
Solution Approach 1:
The patent segments the software update process by allowing centralized core application updates while maintaining tenant-specific customization layers. Each tenant's virtual environment can retain their customized features and security policies even after core updates, resolving the contradiction between maintenance efficiency and customization.
Data Source
AI summary
An extensible servicing hosting platform is provided that supports the design, build and concurrent deployment of multiple web accessible services on a services hosting platform. The services hosting platform comprises a services hosting framework capable of hosting multiple service applications, each of which may be shared by multiple tenants that each customize their use of a particular application service by extending the application service to exploit run time platform services within a service execution pipeline. The services hosting framework may easily be leveraged by applications to decrease the time associated with developing, deploying and maintaining high quality services in a cost effective manner.


