Tenant User Manager for Secure Multi-Tenant Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

There is a need for a user management technology that enhances security and convenience for network services, particularly in managing user access and authentication across various types of network services, while maintaining flexibility and avoiding information leakage or unauthorized access.

Innovation Solution

A computer system architecture that includes a tenant creation system and a tenant operating system, with a tenant user manager for authenticating and authorizing users, separated from the tenant creation system, allowing for secure and flexible user management across multiple tenants.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If user management is integrated into the tenant creation system, then device complexity is reduced, but security and isolation between tenants deteriorate

Engineering Contradiction:
Improvesystem complexityVSAvoidsecurity
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent divides the user management functionality into a separate tenant user manager component that is independent from the tenant creation system. This segmentation allows the tenant creation system to remain simple while the user manager handles security and authentication tasks, thus resolving the contradiction between system complexity and security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a tenant user manager as an intermediary component between users and the tenant creation system. This mediator handles all authentication and authorization operations, providing security isolation while allowing the tenant creation system to focus on its core functionality without direct user management responsibilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If user management is separated into a independent tenant user manager, then security and isolation are improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments user management functions into a dedicated tenant user manager, which improves security through isolation. The modular design allows this separate component to be implemented and maintained independently, managing the complexity increase through structured organization rather than uncontrolled system growth.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The tenant user manager is designed as a universal component that handles multiple user management tasks (authentication, authorization, credential verification) across different tenants. This multi-functionality consolidates complexity into a single specialized component rather than distributing it across multiple locations in the system.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Ease of operation

If centralized user management is used, then ease of operation is improved, but information leakage risk increases

Engineering Contradiction:
Improveuser management convenienceVSAvoidinformation leakage risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent segments the user management system into isolated tenant user managers for each tenant. This segmentation maintains ease of operation through standardized interfaces while preventing information leakage by ensuring that user data and credentials remain isolated within their respective tenant boundaries, cannot be accessed by other tenants.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The tenant user manager acts as an intermediary that handles all user credentials and authentication data. This mediator layer provides a controlled interface for user management operations while preventing direct access to sensitive information, thus maintaining operational convenience without exposing users to information leakage risks.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20230394126A1Computer system and user management method
Publication Date: 2023.12.07 RAKUTEN MOBILE INC
  • US20230394126A1 patent drawing
  • US20230394126A1 patent drawing
  • US20230394126A1 patent drawing

AI summary

In a computer system, a tenant administrator performs user registration into and a login to a purchase manager, and then makes a request to purchase a tenant. Registered user information is stored into a marketplace user manager. An E2EO unit creates a tenant and then creates, for each tenant, a tenant user manager structured to authenticate and authorize a general user of a service. When a user who has performed the user registration into the purchase manager uses the service of the tenant, the tenant user manager delegates processing to the marketplace user manager.