IP Library Granted Patent US 9,003,502
Granted Patent B2
US 9,003,502 · App. 13/819,715 · Granted Apr 7, 2015

Hybrid multi-tenancy cloud platform

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,003,502
App. No.
13/819,715
Granted
Apr 7, 2015
Kind
B2
Abstract

Technologies are presented for a hybrid cloud-based service model combining separate database/separate schema, shared database/separate schema, and shared database/shared schema architectures suitable for serving multiple tenants while addressing varying security needs. Roles and security level needs of different tenants may be determined based on tenant declaration or inference from tenant attributes. Tenants may then be assigned to suitable clouds or sub-clouds based on their security level needs. In some examples, a claims-based access control authorization model such as federation may be employed to support interactions between the three different types of clouds or sub-clouds under the umbrella of a single cloud-based service provider while maintaining application and data security.

Claims (34)

1. A method to provide a hybrid, multi-tenancy cloud platform, the method comprising:

determining a desired security level for one or more applications of a tenant of a cloud service;

based on the desired security level of each of the one or more applications of the tenant, assigning each of the one or more applications to one of:

a first sub-cloud comprising separate data stores for each tenant, or

a second sub-cloud comprising one or more shared data stores for a group of tenants and separate schemas for each tenant; and

in response to detecting a change of the desired security level of at least one of the one or more applications of the tenant, reassigning the at least one application to a different sub-cloud based on a new desired security level determined for the at least one application to address changing security needs of the at least one application, wherein the desired security level and the new desired security level are inferred from one or more tenant attributes that include at least one from a data recovery need, a data protection need, a deployment efficiency, and a number of prospective clients to access tenant data.

2. The method according to claim 1 , further comprising:

based on the desired security level of each of the one or more applications of the tenant, assigning the one or more applications to a third sub-cloud comprising one or more shared data stores and one or more shared schemas for a group of tenants.

3. The method according to claim 1 , wherein the cloud platform provides a software as a service (SaaS).

4. The method of claim 1 , further comprising:

managing the first sub-cloud, the second sub-cloud, and a third sub-cloud through identity federation.

5. The method according to claim 4 , wherein managing the first sub-cloud, the second sub-cloud, and the third sub-cloud through identity federation includes a claim based authentication process establishing trust between the first sub-cloud, the second sub-cloud, and the third sub-cloud through a federation server.

6. A cloud-based system configured to provide a hybrid, multi-tenancy cloud platform, the system comprising:

a management server configured to:

determine a desired security level for one or more applications of a tenant of the cloud platform;

based on the desired security level of each of the one or more applications of the tenant, assign each of the one or more applications to one of:

a first sub-cloud comprising separate data stores for each tenant, or

a second sub-cloud comprising one or more shared data stores for a group of tenants and separate schemas for each tenant; and

in response to detecting a change of the desired security level of at least one of the one or more applications of the tenant, reassign the at least one application to a different sub-cloud based on a new desired security level determined for the at least one application to address changing security needs of the at least one application, wherein the desired security level and the new desired security level are inferred from one or more tenant attributes; and

a federation server configured to:

manage the first sub-cloud, the second sub-cloud, and a third sub-cloud through identity federation.

7. The system according to claim 6 , wherein the management server is further configured to:

based on the desired security level of each of the one or more applications of the tenant, assign the one or more applications to the third sub-cloud comprising one or more shared data stores and one or more shared schemas for a group of tenants.

8. The system according to claim 6 , wherein the one or more tenant attributes include at least one a data recovery need, a data protection need, a deployment efficiency, and a number of prospective clients to access tenant data.

9. The system according to claim 6 , wherein the cloud platform provides a software as a service (SaaS).

10. The system according to claim 6 , wherein the federation server is configured to manage the first sub-cloud, the second sub-cloud, and the third sub-cloud through identity federation employing a claim based authentication process establishing trust between the first sub-cloud, the second sub-cloud, and the third sub-cloud.

11. A non-transitory computer-readable storage medium having instructions stored thereon to provide hybrid, multi-tenancy cloud platforms, the instructions comprising:

determining a desired security level for one or more applications of a tenant of a cloud service;

based on the desired security level of each of the one or more applications of the tenant, assigning each of the one or more applications to one of:

a first sub-cloud comprising separate data stores for each tenant, and

a second sub-cloud comprising one or more shared data stores for a group of tenants and separate schemas for each tenant; and

in response to detecting a change of the desired security level of at least one of the one or more applications of the tenant, reassigning the at least one application to a different sub-cloud based on a new desired security level determined for the at least one application to address changing security needs of the at least one application, wherein the desired security level and the new desired security level are inferred from one or more tenant attributes.

12. The non-transitory computer-readable storage medium according to claim 11 , wherein the instructions further comprise:

based on the desired security level of each of the one or more applications of the tenant, assigning the one or more applications to a third sub-cloud comprising one or more shared data stores and one or more shared schemas for a group of tenants.

Assignments (6)
RELEASE OF SECURITY INTEREST IN PATENTS, RECORDED ON JANUARY 29, 2019 AT REEL 048373 FRAME 0217 Recorded Sep 22, 2025
From: CRESTLINE DIRECT FINANCE, L.P., AS COLLATERAL AGENT
To: EMPIRE TECHNOLOGY DEVELOPMENT LLC
Reel/Frame 072936/0464 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 4, 2020
From: EMPIRE TECHNOLOGY DEVELOPMENT LLC
To: KNAPP INVESTMENT COMPANY LIMITED
Reel/Frame 051707/0297 →
RELEASE OF SECURITY INTEREST Recorded Oct 15, 2019
From: CRESTLINE DIRECT FINANCE, L.P.
To: EMPIRE TECHNOLOGY DEVELOPMENT LLC
Reel/Frame 050722/0481 →
SECURITY INTEREST Recorded Jan 29, 2019
From: EMPIRE TECHNOLOGY DEVELOPMENT LLC
To: CRESTLINE DIRECT FINANCE, L.P.
Reel/Frame 048373/0217 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 28, 2013
From: BEIJING ENDLESS TIME AND SPACE TECHNOLOGY CO., LTD.
To: EMPIRE TECHNOLOGY DEVELOPMENT LLC
Reel/Frame 029891/0152 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 28, 2013
From: CAO, JUNWEI; ZHANG, FAN
To: BEIJING ENDLESS TIME AND SPACE TECHNOLOGY CO., LTD.
Reel/Frame 029891/0158 →