Tenant User Manager for Secure Multi-Tenant Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
There is a need for a user management technology that enhances security and convenience for network services, particularly in managing user access and authentication across various types of network services, while maintaining flexibility and avoiding information leakage or unauthorized access.
Innovation Solution
A computer system architecture that includes a tenant creation system and a tenant operating system, with a tenant user manager for authenticating and authorizing users, separated from the tenant creation system, allowing for secure and flexible user management across multiple tenants.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If user management is integrated into the tenant creation system, then device complexity is reduced, but security and isolation between tenants deteriorate
Solution Approach 1:
The patent divides the user management functionality into a separate tenant user manager component that is independent from the tenant creation system. This segmentation allows the tenant creation system to remain simple while the user manager handles security and authentication tasks, thus resolving the contradiction between system complexity and security.
Solution Approach 2:
The patent introduces a tenant user manager as an intermediary component between users and the tenant creation system. This mediator handles all authentication and authorization operations, providing security isolation while allowing the tenant creation system to focus on its core functionality without direct user management responsibilities.
2Reliability
If user management is separated into a independent tenant user manager, then security and isolation are improved, but device complexity increases
Solution Approach 1:
The patent segments user management functions into a dedicated tenant user manager, which improves security through isolation. The modular design allows this separate component to be implemented and maintained independently, managing the complexity increase through structured organization rather than uncontrolled system growth.
Solution Approach 2:
The tenant user manager is designed as a universal component that handles multiple user management tasks (authentication, authorization, credential verification) across different tenants. This multi-functionality consolidates complexity into a single specialized component rather than distributing it across multiple locations in the system.
3Ease of operation
If centralized user management is used, then ease of operation is improved, but information leakage risk increases
Solution Approach 1:
The patent segments the user management system into isolated tenant user managers for each tenant. This segmentation maintains ease of operation through standardized interfaces while preventing information leakage by ensuring that user data and credentials remain isolated within their respective tenant boundaries, cannot be accessed by other tenants.
Solution Approach 2:
The tenant user manager acts as an intermediary that handles all user credentials and authentication data. This mediator layer provides a controlled interface for user management operations while preventing direct access to sensitive information, thus maintaining operational convenience without exposing users to information leakage risks.
Data Source
AI summary
In a computer system, a tenant administrator performs user registration into and a login to a purchase manager, and then makes a request to purchase a tenant. Registered user information is stored into a marketplace user manager. An E2EO unit creates a tenant and then creates, for each tenant, a tenant user manager structured to authenticate and authorize a general user of a service. When a user who has performed the user registration into the purchase manager uses the service of the tenant, the tenant user manager delegates processing to the marketplace user manager.


