Tenant-Specific Cloud Logging via Metamodel Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current logging systems in cloud-based environments lack the ability to provide tenant-specific monitoring and logging, leading to inefficient resource usage and security concerns, as they often rely on default logging capabilities that can result in unnecessary data collection and potential exposure to unauthorized access.

Innovation Solution

A tenant-specific log system is established using a metamodel that identifies and tracks events on specific resources for a particular tenant, allowing for the transfer of operations to a local device when an unauthorized party accesses the hardware, thereby ensuring secure and efficient resource usage.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If default logging capabilities are used in cloud-based environments, then logging operations are simplified and can be performed on any resource, but this results in unnecessary data collection and potential exposure to unauthorized access

Engineering Contradiction:
Improvelogging operation simplicityVSAvoidunauthorized access exposure
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The logging system is segmented into tenant-specific instances, where each tenant has their own dedicated log on a specific resource. This segmentation isolates logging operations to only the necessary data for each tenant, eliminating unnecessary data collection and reducing exposure to unauthorized access while maintaining operational simplicity through automated tenant-specific log management.

Inventive Principle:
Principle #1Segmentation

2Object-affected harmful factors

If tenant-specific logging is implemented to improve security, then unauthorized access exposure is reduced, but the complexity of the logging system increases

Engineering Contradiction:
Improveunauthorized access exposureVSAvoidlogging system complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The system implements self-service automated processes for creating and managing tenant-specific logs. When a new tenant is added or resources are allocated, the system automatically creates the appropriate tenant-specific log on the designated resource without requiring manual configuration. This automation reduces the perceived complexity for users while maintaining the security benefits of tenant-specific logging.

Inventive Principle:
Principle #25Self-service

3Object-affected harmful factors

If operations are transferred to local devices upon detecting unauthorized access, then security is enhanced, but the time required to respond to and mitigate security threats increases

Engineering Contradiction:
Improvesecurity vulnerabilityVSAvoidresponse time
Core Design Contradiction:
Object-affected harmful factorsVSLoss of time

Solution Approach 1:

The system performs preliminary actions by continuously monitoring resources for unauthorized access attempts and pre-configuring transfer protocols before incidents occur. When unauthorized access is detected, the system can rapidly execute pre-planned transfer operations to move data or operations to secure local devices, significantly reducing response time while maintaining enhanced security posture.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10171291B2Tenant-specific log for events related to a cloud-based service
Publication Date: 2019.01.01 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US10171291B2 patent drawing
  • US10171291B2 patent drawing
  • US10171291B2 patent drawing

AI summary

A method, system, and/or computer program product establishes and utilizes a tenant-specific log for events related to a cloud-based service. A metamodel is created for a cloud-based service provided to a specific tenant of a cloud. The metamodel describes types of resources that are providing the cloud-based service that the specific tenant desires to monitor. In response to the cloud-based service being executed, the metamodel is used to identify a set of resources that are actually providing the cloud-based service for the specific tenant. A tenant-specific log is established to tracks events that occur on each actual resource from the set of resources, and records access to the specific unit of hardware by an authorized user of the specific unit of hardware. Operations related to the cloud-based service are transferred from the specific unit of hardware to a local device that is available only to the specific tenant.