Shared Cloud Usage Records With Blockchain Tenant Isolation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Maintaining accurate and secure usage audit logs in shared cloud-computing environments is challenging due to the difficulty in meeting requirements such as non-repudiation, sequence integrity, proof of reliable audit, performance, scalability, isolation of tenant audit, security, and durability, especially when resources are shared among multiple organizations/tenants.
Innovation Solution
A method and system utilizing blockchain technology to create and maintain audit logs, incorporating audit trail adapters, load balancers, and blockchain data structures to ensure secure and scalable logging of resource usage across multiple entities, with features like synchronized timestamps and pseudonymization to protect sensitive data.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If traditional centralized audit logging is used in shared cloud environments, then implementation is simpler, but security and tenant isolation are compromised
Solution Approach 1:
The patent segments the centralized audit log into tenant-specific partitions using blockchain technology. Each tenant's audit records are stored in isolated segments of the distributed ledger, ensuring that while the system remains distributed and secure, each organization's audit data is independently protected and cannot be accessed by other tenants. This resolves the contradiction by maintaining simplicity through automated segmentation while achieving strong security and isolation.
Solution Approach 2:
The patent introduces a blockchain-based intermediary layer between the cloud infrastructure and audit logging functions. This intermediary provides a trusted, decentralized mechanism for recording and verifying audit events without requiring direct access to underlying infrastructure, thereby maintaining security and tenant isolation while keeping the implementation relatively simple through standardized blockchain interfaces.
2Reliability
If distributed blockchain audit logging is implemented, then security and tenant isolation are improved, but system complexity increases
Solution Approach 1:
The patent implements a universal blockchain-based audit logging system that serves multiple functions: it provides tenant isolation, ensures data integrity, enables secure access control, and maintains audit trails across different cloud services. By using a single multi-functional blockchain infrastructure rather than separate solutions for each requirement, the system achieves high reliability without proportionally increasing complexity.
Solution Approach 2:
The blockchain audit logging system operates autonomously through self-service mechanisms including automatic event capture, decentralized verification, and automated tenant isolation enforcement. The system validates and records audit events without requiring manual intervention or complex centralized management, thereby improving security and isolation while keeping operational complexity manageable through automation.
3Measurement precision
If detailed audit logs are maintained for all tenants, then audit accuracy is improved, but performance and scalability deteriorate
Solution Approach 1:
The patent applies local quality by allowing each tenant to have customized audit logging configurations tailored to their specific compliance and monitoring needs. The blockchain system efficiently manages these varied requirements by processing and storing only the relevant audit events for each tenant, rather than uniformly logging all possible events across the entire system. This maintains high audit accuracy for each tenant while optimizing overall system performance through selective event capture and storage.
4Ease of operation
If audit logs are accessible to all authorized users, then ease of access is improved, but security is worsened
Solution Approach 1:
The patent implements preliminary action by establishing tenant-specific access controls and permissions before any audit log access occurs. The blockchain system pre-configures which users can access which tenant's audit data based on their organizational affiliations and authorization levels. This ensures that when users access audit logs, they can do so easily within their authorized scope without risking exposure to unauthorized data, as the security boundaries are already in place.
Data Source
Figure 1
Figure 2A
Figure 2B
AI summary
A method for maintaining a log of events in a shared computing environment is provided. One example of the disclosed method includes receiving one or more data streams from the shared computing environment that include transactions conducted in the shared computing environment by a first entity and a second entity that is different from the first entity. The method further includes creating a first blockchain entry for a first transaction conducted in the shared computing environment for the first entity, creating a second blockchain entry for a second transaction conducted in the shared computing environment for the second entity, where the second blockchain entry includes a signature that points to the first blockchain entry, and then causing the first and second blockchain entries to be written to a common blockchain data structure in a database that is made accessible to both the first entity and the second entity.