Tenant Separation via Token Injection in Cloud Analytics

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cloud-based analytics systems face challenges in preserving tenant separation during live data connections with various application systems, as each system has a unique data structure, requiring unique handling to expose data effectively to users.

Innovation Solution

A tenant separation architecture is implemented, using a token-based authentication method where an authentication token with a tenant identifier is injected into multiple modules of the application datacenter, configuring structural parts to execute only for the associated tenant data, ensuring separation across application server, database, and analytics layers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a cloud-based analytics system integrates with multiple application systems having unique data structures, then the analytics capability and data exposure effectiveness are improved, but the complexity of preserving tenant separation increases

Engineering Contradiction:
Improveanalytics capabilityVSAvoidtenant separation complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces an authentication token as an intermediary carrier that transports tenant identification information between the analytics application and multiple application systems. This token acts as a mediator that enables the system to handle diverse data structures from different tenants without requiring complex custom integration logic for each system, thereby resolving the contradiction between adaptability and complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system dynamically changes the tenant identification parameter embedded in the authentication token based on the user's context and the specific application system being accessed. This parameter change mechanism allows the same integration architecture to adapt to different tenants and data structures without increasing structural complexity, as the system adjusts the tenant parameter rather than reconfiguring the entire integration framework.

Inventive Principle:
Principle #35Parameter changes

2Ease of operation

If unique handling is implemented for each application system with unique data structure, then data exposure effectiveness is improved, but the system complexity and maintenance burden increase

Engineering Contradiction:
Improvedata exposure effectivenessVSAvoidsystem complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The authentication token mechanism serves as a universal solution that works across all application systems regardless of their unique data structures. Instead of implementing separate handling logic for each system, the patent creates a multi-functional token-based approach that can carry tenant information through any system interface, thereby improving data exposure effectiveness while avoiding the complexity of custom integrations for each application system.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If tenant separation is maintained across all modules, then data privacy and compliance are improved, but the integration flexibility with various OEM systems decreases

Engineering Contradiction:
Improvedata privacyVSAvoidintegration flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements preliminary action by embedding the tenant identification information into the authentication token before the data access operation occurs. This advance preparation ensures that tenant separation is automatically enforced throughout the entire data access workflow across all OEM systems, without requiring complex runtime checks or adaptations. The tenant context is pre-established, allowing flexible integration while maintaining privacy through automated enforcement.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11550940B2Tenant separation for analytical applications in a remote application integration scenario
Publication Date: 2023.01.10 SAP SE
  • US11550940B2 patent drawing
  • US11550940B2 patent drawing
  • US11550940B2 patent drawing

AI summary

A tenant separation architecture is provided to adopt tenant separation for remote integration of various OEM systems with a cloud-based analytics application. The tenant separation architecture provided herein allows for tenant separation in a wide range of modules in different OEM integration scenarios through a token-base authentication. Application server tenants and database tenants may be accessed for application of the tenant separation. Moreover, the tenant separation implementations disclosed herein may be applied to different modules for metadata, tenant configuration, authorization concepts, and general data protection regulation (GDPR) adoption.