Scope-Based Certificate Deployment for Multi-Tenant Cloud Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cloud-based content and collaboration services, such as Microsoft SharePoint Online, require dedicated environments for each tenant, leading to burdensome management and scaling issues due to the need for hundreds of certificates, dedicated hardware, and isolated networking equipment, which is expensive and resource-intensive.

Innovation Solution

The implementation of scope-based certificate deployment allows for secure, dedicated tenant access in multi-tenant environments by using tenant-specific certificates that can be scoped to specific machines or content farms, reducing the number of certificates needed and enabling side-by-side data storage for dedicated and non-dedicated tenants, while maintaining enhanced security through isolated certificates.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If dedicated environments are used for each tenant, then security and dedicated access are improved, but device complexity and management burden increase significantly

Engineering Contradiction:
ImprovesecurityVSAvoidmanagement burden
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the certificate management system by introducing scope-based certificates that are divided into multiple identity portions (first identity portion and second identity portion). This allows different tenants to have isolated certificate segments within a shared environment, providing dedicated security without requiring complete environmental isolation. Each tenant's certificate scope is segmented to prevent interference with other tenants while maintaining security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements a universal certificate structure that serves multiple tenants simultaneously. The scope-based certificate design allows a single certificate infrastructure to support both dedicated tenant access and multi-tenant sharing through the use of identity portions and scope validation. This multi-functional approach eliminates the need for completely separate dedicated environments for each tenant.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If hundreds of certificates are managed for each dedicated tenant, then security is maintained, but loss of time and processing resources increase

Engineering Contradiction:
ImprovesecurityVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent merges multiple certificate functions into a single scope-based certificate structure. Instead of managing hundreds of separate certificates for each tenant, the system combines identity verification, scope validation, and tenant isolation into one unified certificate mechanism. This merging dramatically reduces the number of certificates that need to be issued, stored, and validated.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The scope-based certificate serves multiple security functions simultaneously: it provides tenant identification, defines access scope, enables isolation between tenants, and validates permissions. This multi-functionality replaces what would otherwise require numerous separate certificates, reducing processing overhead and management time.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If dedicated environments with isolated networking equipment are used, then tenant isolation is improved, but device complexity and resource requirements increase

Engineering Contradiction:
Improvetenant isolationVSAvoidnetworking complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces scope-based certificates as an intermediary mechanism that enables tenant isolation without physical network separation. The certificate structure acts as a logical mediator that enforces tenant boundaries and access rules within a shared networking infrastructure. This intermediary approach provides isolation equivalent to dedicated environments while using shared resources.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent moves the isolation mechanism from the physical/network dimension to the logical/certificate dimension. Instead of isolating tenants through separate networking equipment (physical dimension), the system implements isolation through scope validation and identity portions in the certificate structure (logical dimension). This dimensional shift allows sharing of physical resources while maintaining logical isolation.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

4Productivity

If scope-based certificate deployment is implemented, then scalability and resource efficiency are improved, but device complexity increases

Engineering Contradiction:
ImprovescalabilityVSAvoidcertificate structure complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The certificate structure is segmented into distinct identity portions and scope components that can be independently managed and validated. This segmentation allows the system to scale by adding tenants without requiring complete reconfiguration of the certificate infrastructure. Each tenant receives a certificate with their specific identity portions and scope definitions, enabling linear scalability.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS10320572B2Scope-based certificate deployment
Publication Date: 2019.06.11 MICROSOFT TECHNOLOGY LICENSING LLC
  • US10320572B2 patent drawing
  • US10320572B2 patent drawing
  • US10320572B2 patent drawing

AI summary

The techniques described herein facilitate scope-based certificate deployment for secure dedicated tenant access in multi-tenant, cloud-based content and collaboration environments. In some embodiments, a method is described that includes receiving an incoming authentication request from an access system, wherein the authentication request includes metadata, extracting the metadata from the authentication request, and processing the metadata to identify a tenant corresponding to the request. A tenant-specific certificate associated with the tenant is then accessed and provided to the access system for validation by a third-party certificate authority.