Tenant Certificate Isolation in Cloud Connection Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cloud service connection management systems face challenges in securing connections between information processing terminals and back-end systems, as they either require managing multiple execution platforms for each tenant, increasing complexity, or using a shared platform which necessitates preventing unauthorized access across tenants, compromising security.

Innovation Solution

A connection management device that receives and manages certificates for multiple external systems, using a specific certificate for each tenant to establish secure connections, with an independent storage system to prevent access to certificates belonging to other tenants, thereby enhancing security and reducing the need for multiple execution platforms.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If a shared execution platform is used for multiple tenants, then device complexity is reduced, but security is compromised due to potential unauthorized access across tenants

Engineering Contradiction:
Improveexecution platform management complexityVSAvoidconnection security
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent segments certificate management by creating separate certificate storage areas for each tenant within the shared execution platform. Each tenant's certificates are stored in isolated storage regions (e.g., different database tables or encrypted storage segments), preventing cross-tenant access while maintaining a single unified execution platform. This segmentation approach resolves the contradiction by enabling resource sharing while enforcing security boundaries.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a certificate management intermediary layer that sits between the execution platform and external systems. This intermediary handles certificate selection, validation, and management operations, ensuring that each tenant can only access their own certificates through controlled interfaces. The intermediary enforces security policies while allowing the shared platform to operate efficiently, thus maintaining both security and low complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If multiple execution platforms are managed for each tenant, then security is improved through isolation, but device complexity increases significantly

Engineering Contradiction:
Improveconnection securityVSAvoidexecution platform management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges multiple tenant-specific certificate management functions into a single unified execution platform. Instead of maintaining separate execution platforms for each tenant, the system combines all tenant operations into one platform while using logical isolation mechanisms (such as tenant identifiers, access control lists, and separate certificate storage regions) to maintain security. This merging approach reduces device complexity while preserving security through logical rather than physical separation.

Inventive Principle:
Principle #5Merging (Combining)

3Device complexity

If certificate storage is shared across tenants, then device complexity is reduced, but security is compromised due to potential certificate access by unauthorized tenants

Engineering Contradiction:
Improvecertificate management complexityVSAvoidcertificate access security
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent applies local quality by creating distinct storage regions within the shared certificate storage system, where each region is specifically designated for a particular tenant's certificates. Each storage region has localized access controls and metadata tags that enforce tenant-specific permissions. This approach allows the system to maintain a single shared storage infrastructure (reducing complexity) while ensuring that each tenant can only access their own certificates (maintaining security) through localized access restrictions.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS10454920B2Non-transitory computer-readable recording medium, connection management method, and connection management device
Publication Date: 2019.10.22 FUJITSU LTD
  • US10454920B2 patent drawing
  • US10454920B2 patent drawing
  • US10454920B2 patent drawing

AI summary

A non-transitory computer-readable recoding medium having stored therein a connection management program that causes a computer to execute a process that includes receiving registrations of a plurality of certificates, the plurality of certificates respectively being used to establish connections to a plurality of external systems, respectively, the plurality of external systems respectively relating to a plurality of tenants, respectively, whose connections are managed by the computer, and establishing a connection to a specific external system using a specific certificate when a information processing terminal associated with a specific tenant is connecting to the specific external system, the specific certificate corresponding both to the specific tenant and the specific external system, the specific external system being included in the plurality of external systems.