Shared Cloud Usage Records With Blockchain Tenant Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Maintaining accurate and secure usage audit logs in shared cloud-computing environments is challenging due to the difficulty in meeting requirements such as non-repudiation, sequence integrity, proof of reliable audit, performance, scalability, isolation of tenant audit, security, and durability, especially when resources are shared among multiple organizations/tenants.

Innovation Solution

A method and system utilizing blockchain technology to create and maintain audit logs, incorporating audit trail adapters, load balancers, and blockchain data structures to ensure secure and scalable logging of resource usage across multiple entities, with features like synchronized timestamps and pseudonymization to protect sensitive data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If traditional centralized audit logging is used in shared cloud environments, then implementation is simpler, but security and tenant isolation are compromised

Engineering Contradiction:
Improveaudit logging implementationVSAvoidtenant isolation and security
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent segments the centralized audit log into tenant-specific partitions using blockchain technology. Each tenant's audit records are stored in isolated segments of the distributed ledger, ensuring that while the system remains distributed and secure, each organization's audit data is independently protected and cannot be accessed by other tenants. This resolves the contradiction by maintaining simplicity through automated segmentation while achieving strong security and isolation.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a blockchain-based intermediary layer between the cloud infrastructure and audit logging functions. This intermediary provides a trusted, decentralized mechanism for recording and verifying audit events without requiring direct access to underlying infrastructure, thereby maintaining security and tenant isolation while keeping the implementation relatively simple through standardized blockchain interfaces.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If distributed blockchain audit logging is implemented, then security and tenant isolation are improved, but system complexity increases

Engineering Contradiction:
Improvetenant isolation and securityVSAvoidaudit logging system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal blockchain-based audit logging system that serves multiple functions: it provides tenant isolation, ensures data integrity, enables secure access control, and maintains audit trails across different cloud services. By using a single multi-functional blockchain infrastructure rather than separate solutions for each requirement, the system achieves high reliability without proportionally increasing complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The blockchain audit logging system operates autonomously through self-service mechanisms including automatic event capture, decentralized verification, and automated tenant isolation enforcement. The system validates and records audit events without requiring manual intervention or complex centralized management, thereby improving security and isolation while keeping operational complexity manageable through automation.

Inventive Principle:
Principle #25Self-service

3Measurement precision

If detailed audit logs are maintained for all tenants, then audit accuracy is improved, but performance and scalability deteriorate

Engineering Contradiction:
Improveaudit accuracyVSAvoidsystem performance
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The patent applies local quality by allowing each tenant to have customized audit logging configurations tailored to their specific compliance and monitoring needs. The blockchain system efficiently manages these varied requirements by processing and storing only the relevant audit events for each tenant, rather than uniformly logging all possible events across the entire system. This maintains high audit accuracy for each tenant while optimizing overall system performance through selective event capture and storage.

Inventive Principle:
Principle #3Local quality

4Ease of operation

If audit logs are accessible to all authorized users, then ease of access is improved, but security is worsened

Engineering Contradiction:
Improvelog accessVSAvoiddata exposure risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent implements preliminary action by establishing tenant-specific access controls and permissions before any audit log access occurs. The blockchain system pre-configures which users can access which tenant's audit data based on their organizational affiliations and authorization levels. This ensures that when users access audit logs, they can do so easily within their authorized scope without risking exposure to unauthorized data, as the security boundaries are already in place.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP3797369B1System and method for maintaining usage records in a shared computing environment
Publication Date: 2025.09.03 ASSA ABLOY AB
  • EP3797369B1 patent drawingFigure 1
  • EP3797369B1 patent drawingFigure 2A
  • EP3797369B1 patent drawingFigure 2B

AI summary

A method for maintaining a log of events in a shared computing environment is provided. One example of the disclosed method includes receiving one or more data streams from the shared computing environment that include transactions conducted in the shared computing environment by a first entity and a second entity that is different from the first entity. The method further includes creating a first blockchain entry for a first transaction conducted in the shared computing environment for the first entity, creating a second blockchain entry for a second transaction conducted in the shared computing environment for the second entity, where the second blockchain entry includes a signature that points to the first blockchain entry, and then causing the first and second blockchain entries to be written to a common blockchain data structure in a database that is made accessible to both the first entity and the second entity.