Tenant Data Residency Enforcement in Multitenant Cloud Platforms

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional multitenant cloud collaboration platforms face challenges in ensuring data residency requirements, as all tenants' data is stored in the same physical location, making it difficult for tenants to certify or guarantee that their data is physically resident in a specific location or jurisdiction, which is a regulatory and compliance issue.

Innovation Solution

A multitenant query gateway system that determines the physical location of data lakes based on tenant-specific requests and dynamically instantiates new data lakes in requested regions, allowing data to be stored in compliance with specific residency requirements by leveraging hosting platform interfaces and APIs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of energy

If all tenants' data is stored in a single multitenant data lake for cost and efficiency, then infrastructure cost and operational efficiency are improved, but the ability to guarantee data residency in specific locations is lost

Engineering Contradiction:
Improveinfrastructure costVSAvoiddata residency compliance
Core Design Contradiction:
Loss of energyVSAdaptability or versatility

Solution Approach 1:

The patent segments the single multitenant data lake into multiple tenant-specific data lakes, where each data lake is dedicated to a specific tenant and can be located in different geographic regions. This segmentation allows each tenant to have their data stored in compliance with their specific residency requirements while still using a shared infrastructure platform.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements local quality by allowing different data lakes to have different geographic locations based on tenant requirements. Each tenant's data is stored in a data lake located in the specific region or jurisdiction required by their compliance policies, while the overall system maintains a unified architecture for efficient resource sharing.

Inventive Principle:
Principle #3Local quality

2Reliability

If tenant-specific data is isolated and encrypted in the same physical storage, then data security between tenants is improved, but the ability to certify physical data location is lost

Engineering Contradiction:
Improvedata securityVSAvoiddata location certification
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent segments the storage infrastructure into separate tenant-specific data lakes, eliminating the need for encryption-based isolation while maintaining security through physical separation. Each tenant's data resides in its own dedicated data lake, providing both security and location certification capabilities simultaneously.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a data lake manager as an intermediary component that handles data placement, migration, and location tracking. This mediator maintains the mapping between tenants and their data lake locations, enabling certification of physical data location while the underlying storage infrastructure remains unified.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Device complexity

If a single data lake is used for all tenants, then infrastructure complexity is reduced, but compliance with regional data residency regulations becomes impossible

Engineering Contradiction:
Improveinfrastructure complexityVSAvoidregulatory compliance
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The patent creates a universal data lake management system that can handle multiple compliance requirements through a single platform. The data lake manager provides multi-functional capabilities including automated data placement, location tracking, and compliance verification, allowing the system to serve multiple regulatory jurisdictions without requiring separate infrastructure for each.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent implements dynamic data lake creation and management, where data lakes can be instantiated, moved, or replicated based on changing compliance requirements. The system dynamically adjusts data storage locations and can create new data lakes in different regions as regulatory requirements change, maintaining compliance without fixed infrastructure configurations.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS20240370830A1Tenant data residency requirements enforcement in multitenant collaborative work environments
Publication Date: 2024.11.07 ATLASSIAN PTY LTD
  • US20240370830A1 patent drawing
  • US20240370830A1 patent drawing
  • US20240370830A1 patent drawing

AI summary

A multitenant collaboration tool is instantiated over physical infrastructure operated by a hosting platform. The multitenant collaboration tool leverages interfaces of the hosting platform to provision and/or instantiate buckets and/or data lakes in particular physical locations, serving from those data lakes tenant data required to be stored within those specified locations. The multitenant collaboration tool includes a multitenant query gateway configured to route data queries from client devices to appropriate multitenant data lakes associated with multitenant collaboration tool.