Tenant Separation via Token Injection in Cloud Analytics
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing cloud-based analytics systems face challenges in preserving tenant separation during live data connections with various application systems, as each system has a unique data structure, requiring unique handling to expose data effectively to users.
Innovation Solution
A tenant separation architecture is implemented, using a token-based authentication method where an authentication token with a tenant identifier is injected into multiple modules of the application datacenter, configuring structural parts to execute only for the associated tenant data, ensuring separation across application server, database, and analytics layers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a cloud-based analytics system integrates with multiple application systems having unique data structures, then the analytics capability and data exposure effectiveness are improved, but the complexity of preserving tenant separation increases
Solution Approach 1:
The patent introduces an authentication token as an intermediary carrier that transports tenant identification information between the analytics application and multiple application systems. This token acts as a mediator that enables the system to handle diverse data structures from different tenants without requiring complex custom integration logic for each system, thereby resolving the contradiction between adaptability and complexity.
Solution Approach 2:
The system dynamically changes the tenant identification parameter embedded in the authentication token based on the user's context and the specific application system being accessed. This parameter change mechanism allows the same integration architecture to adapt to different tenants and data structures without increasing structural complexity, as the system adjusts the tenant parameter rather than reconfiguring the entire integration framework.
2Ease of operation
If unique handling is implemented for each application system with unique data structure, then data exposure effectiveness is improved, but the system complexity and maintenance burden increase
Solution Approach 1:
The authentication token mechanism serves as a universal solution that works across all application systems regardless of their unique data structures. Instead of implementing separate handling logic for each system, the patent creates a multi-functional token-based approach that can carry tenant information through any system interface, thereby improving data exposure effectiveness while avoiding the complexity of custom integrations for each application system.
3Reliability
If tenant separation is maintained across all modules, then data privacy and compliance are improved, but the integration flexibility with various OEM systems decreases
Solution Approach 1:
The patent implements preliminary action by embedding the tenant identification information into the authentication token before the data access operation occurs. This advance preparation ensures that tenant separation is automatically enforced throughout the entire data access workflow across all OEM systems, without requiring complex runtime checks or adaptations. The tenant context is pre-established, allowing flexible integration while maintaining privacy through automated enforcement.
Data Source
AI summary
A tenant separation architecture is provided to adopt tenant separation for remote integration of various OEM systems with a cloud-based analytics application. The tenant separation architecture provided herein allows for tenant separation in a wide range of modules in different OEM integration scenarios through a token-base authentication. Application server tenants and database tenants may be accessed for application of the tenant separation. Moreover, the tenant separation implementations disclosed herein may be applied to different modules for metadata, tenant configuration, authorization concepts, and general data protection regulation (GDPR) adoption.


