Tenant Data Residency Enforcement in Multitenant Cloud Platforms
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional multitenant cloud collaboration platforms face challenges in ensuring data residency requirements, as all tenants' data is stored in the same physical location, making it difficult for tenants to certify or guarantee that their data is physically resident in a specific location or jurisdiction, which is a regulatory and compliance issue.
Innovation Solution
A multitenant query gateway system that determines the physical location of data lakes based on tenant-specific requests and dynamically instantiates new data lakes in requested regions, allowing data to be stored in compliance with specific residency requirements by leveraging hosting platform interfaces and APIs.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of energy
If all tenants' data is stored in a single multitenant data lake for cost and efficiency, then infrastructure cost and operational efficiency are improved, but the ability to guarantee data residency in specific locations is lost
Solution Approach 1:
The patent segments the single multitenant data lake into multiple tenant-specific data lakes, where each data lake is dedicated to a specific tenant and can be located in different geographic regions. This segmentation allows each tenant to have their data stored in compliance with their specific residency requirements while still using a shared infrastructure platform.
Solution Approach 2:
The patent implements local quality by allowing different data lakes to have different geographic locations based on tenant requirements. Each tenant's data is stored in a data lake located in the specific region or jurisdiction required by their compliance policies, while the overall system maintains a unified architecture for efficient resource sharing.
2Reliability
If tenant-specific data is isolated and encrypted in the same physical storage, then data security between tenants is improved, but the ability to certify physical data location is lost
Solution Approach 1:
The patent segments the storage infrastructure into separate tenant-specific data lakes, eliminating the need for encryption-based isolation while maintaining security through physical separation. Each tenant's data resides in its own dedicated data lake, providing both security and location certification capabilities simultaneously.
Solution Approach 2:
The patent introduces a data lake manager as an intermediary component that handles data placement, migration, and location tracking. This mediator maintains the mapping between tenants and their data lake locations, enabling certification of physical data location while the underlying storage infrastructure remains unified.
3Device complexity
If a single data lake is used for all tenants, then infrastructure complexity is reduced, but compliance with regional data residency regulations becomes impossible
Solution Approach 1:
The patent creates a universal data lake management system that can handle multiple compliance requirements through a single platform. The data lake manager provides multi-functional capabilities including automated data placement, location tracking, and compliance verification, allowing the system to serve multiple regulatory jurisdictions without requiring separate infrastructure for each.
Solution Approach 2:
The patent implements dynamic data lake creation and management, where data lakes can be instantiated, moved, or replicated based on changing compliance requirements. The system dynamically adjusts data storage locations and can create new data lakes in different regions as regulatory requirements change, maintaining compliance without fixed infrastructure configurations.
Data Source
AI summary
A multitenant collaboration tool is instantiated over physical infrastructure operated by a hosting platform. The multitenant collaboration tool leverages interfaces of the hosting platform to provision and/or instantiate buckets and/or data lakes in particular physical locations, serving from those data lakes tenant data required to be stored within those specified locations. The multitenant collaboration tool includes a multitenant query gateway configured to route data queries from client devices to appropriate multitenant data lakes associated with multitenant collaboration tool.


