IP Library Granted Patent US 9,411,973
Granted Patent B2
US 9,411,973 · App. 13/875,301 · Granted Aug 9, 2016

Secure isolation of tenant resources in a multi-tenant storage system using a security gateway

Inventors: Michael E. Factor (Haifa, IL); David Hadas (Zichron Yaakov, IL); Elliot K. Kolodner (Haifa, IL); Anil Kurmus (Rueschlikon, CH); Alexandra Shulman-Peleg (Givatayim, IL); Alessandro Sorniotti (Zurich, CH)
Assignee: International Business Machines Corporation
G06F21/6218G06F9/00G06F9/46G06F17/30194G06F21/6281G06F2221/2145
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,411,973
App. No.
13/875,301
Granted
Aug 9, 2016
Kind
B2
Abstract

Machines, systems and methods for handling a client request in a hierarchical multi-tenant data storage system, the method comprising processing a request in subtasks, wherein a subtask is executed with a minimal set of privileges associated with a specific subtenant; extracting a claimed n-level hierarchy of a tenant and sub-tenant identities from the request; extracting authentication signatures or credentials that correspond to a level in the hierarchy; for a first level in the hierarchy, sending the request to a dedicated subtenant authenticator with privilege to validate credentials for a subtenant at the first level; and receiving a confirmation from the dedicated subtenant authenticator, whether the request is authentic.

Claims (29)

1. A method of handling a client request in a hierarchical multi-tenant data storage system, the method comprising:

processing a request in subtasks, wherein a subtask is executed with a minimal set of privileges associated with a specific subtenant;

extracting a claimed n-level hierarchy of a tenant and sub-tenant identities from the request;

extracting authentication signatures or credentials that correspond to a level in the hierarchy;

for a first level in the hierarchy, spawning a dedicated subtenant authenticator;

for a first level in the hierarchy, sending the request to a dedicated subtenant authenticator, wherein the dedicated subtenant authenticator is privileged to validate credentials for a subtenant at only the first level; and

receiving a confirmation from the dedicated subtenant authenticator, whether the request is authentic.

2. The method of claim 1 , wherein in response to receiving a confirmation that the request is authentic, the request is forwarded to one or more entities having a dedicated subtenant privilege for accessing a subset of the subtenant resources.

3. A computer system comprising:

one or more processors;

one or more non-transitory computer readable storage media;

computer program instructions;

the computer program instructions being stored on the one or more non-transitory computer readable storage media;

the computer program instructions comprising instructions to:

process a request in subtasks, wherein a subtask is executed with a minimal set of privileges associated with a specific subtenant;

extract a claimed n-level hierarchy of a tenant and sub-tenant identities from the request

extract authentication signatures or credentials that correspond to a level in the hierarchy;

for a first level in the hierarchy, spawn a dedicated subtenant authenticator;

for the first level in the hierarchy, send the request to dedicated subtenant authenticator, wherein the dedicated subtenant authenticator is privileged to validate credentials for a subtenant at only the first level; and

receive a confirmation from the dedicated subtenant authenticator, whether the request is authentic.

4. The system of claim 3 , wherein in response to receiving a confirmation that the request is authentic, the request is forwarded to one or more entities having a dedicated subtenant privilege for accessing a subset of the subtenant resources.

5. A computer program product comprising logic code embedded in a non-transitory data storage medium for maintaining resource isolation in a multi-tenant computing system, wherein execution of the logic code on a computer causes the computer to:

process a request in subtasks, wherein a subtask is executed with a minimal set of privileges associated with a specific subtenant;

extract a claimed n-level hierarchy of a tenant and sub-tenant identities from the request;

extract authentication signatures or credentials that correspond to a level in the hierarchy;

for a first level in the hierarchy, spawn a dedicated subtenant authenticator;

for the first level in the hierarchy, send the request to dedicated subtenant authenticator, wherein the dedicated subtenant authenticator is privileged to validate credentials for a subtenant at only the first level; and

receive a confirmation from the dedicated subtenant authenticator, whether the request is authentic.

6. The computer program product of claim 5 , wherein in response to receiving a confirmation that the request is authentic, the request is forwarded to one or more entities having a dedicated subtenant privilege for accessing a subset of the subtenant resources.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 27, 2013
From: FACTOR, MICHAEL E; HADAS, DAVID; KOLODNER, ELLIOT K; KURMUS, ANIL; SHULMAN-PELEG, ALEXANDRA; SORNIOTTI, ALESSANDRO
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 030695/0258 →
Continuity (1)
Related Publication 20140330869A1 · Nov 6, 2014