IP Library › Granted Patent US 11,574,068
Granted Patent B2
US 11,574,068 · App. 16/895,948 · Granted Feb 7, 2023

Methods and systems for tenancy in a multitenant environment

Inventors: Peter Varga (Markham, CA); Nicholas Edward Scott (Waterloo, CA)
Assignee: OPEN TEXT SA ULC
G06F21/6218H04L63/102H04L63/105
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,574,068
App. No.
16/895,948
Granted
Feb 7, 2023
Kind
B2
Abstract

Systems, methods and computer program products for controlling access to an organization's data in a multitenant environment are provided. An organization hierarchy is defined at a multitenant platform, the organization hierarchy comprising an organization and a plurality of sites owned by the organization, each of the plurality of sites representing a data isolation boundary for the organization's data. The sites are associated with subscriptions to applications of the multitenant platform. The organization can designate user partitions within the sites, each user partition designating a corresponding set of site users and a corresponding authentication service. the multitenant platform enables access to each subscription of a site only if a site user is authenticated by the authentication service designated in the user partition corresponding to the site user.

Claims (48)

1. A method for controlling access to data in a multitenant environment, the method comprising:

providing a multitenant platform;

executing one or more applications on the multitenant platform;

defining an organization hierarchy in the multitenant platform, the organization hierarchy comprising a first organization at a first hierarchical level and a plurality of sites owned by the first organization at a second hierarchical level lower than the first hierarchical level, each of the plurality of sites representing a data isolation boundary for data of the first organization, each of the plurality of sites associated with one or more subscriptions to the one or more applications;

providing a user interface providing a unified view of the plurality of sites of the first organization,

wherein the multitenant platform enables site-level subscription-based access to the one or more applications;

wherein the multitenant platform enables the first organization to designate a plurality of user partitions within a first site of the plurality of sites, each user partition designating a corresponding set of site users and a corresponding authentication service;

wherein the multitenant platform enables the first organization to authorize a plurality of site users associated with the first site to access the one or more applications associated with the one or more subscriptions associated with that site; and

wherein, for each site user of the plurality of site users associated with the first site, the multitenant platform enables access to each of the one or more subscriptions associated with the first site only if the site user is authenticated by the corresponding authentication service designated in a user partition corresponding to the site user,

wherein each user in the plurality of site users is defined by a combination of an email address and an identifier for the first site.

2. The method of claim 1 , further comprising receiving at the multitenant platform a policy at an organization level of the organization hierarchy and pushing the policy to a site level.

3. The method of claim 1 , wherein the multitenant platform enables a single email address to be used to simultaneously access a first subscription of the first organization as a first user and a second subscription of a second organization as a second user, wherein access of the first user to the first subscription is isolated from access of the second user to the second subscription.

4. The method of claim 1 , wherein the multitenant platform enables a single email address to be used to simultaneously access a first subscription of the first organization as a first user and a second subscription of the first organization as a second user, wherein access of the first user to the first subscription is isolated from access of the second user to the second subscription.

5. The method of claim 1 , wherein at least one of the plurality of user partitions includes an external user external to the first organization.

6. The method of claim 1 , wherein at least one of the plurality of user partitions comprises a first user having an email address that has a domain which is different than a domain of the first site.

7. A computer program product for controlling access to data in a multitenant environment, the computer program product comprising a non-transitory computer-readable medium storing instructions executable by a processor to cause the processor to perform:

providing a multitenant platform;

executing one or more applications on the multitenant platform;

defining an organization hierarchy on the multitenant platform, the organization hierarchy comprising a first organization at a first hierarchical level and a plurality of sites owned by the first organization at a second hierarchical level lower than the first hierarchical level, each of the plurality of sites representing a data isolation boundary for data of the first organization, each of the plurality of sites associated with one or more subscriptions to the one or more applications;

providing a user interface providing a unified view of the plurality of sites of the first organization;

enabling, by the multitenant platform, site-level subscription-based access to the one or more applications;

enabling, by the multitenant platform, the first organization to designate a plurality of user partitions within a first site of the plurality of sites, each user partition designating a corresponding set of site users and a corresponding authentication service;

enabling, by the multitenant platform, the first organization to authorize a plurality of site users associated with the first site to access the one or more applications associated with the one or more subscriptions associated with that site; and

for each site user of the plurality of site users associated with the first site, enabling, by the multitenant platform, access to each of the one or more subscriptions associated with the first site only if the site user is authenticated by the corresponding authentication service designated in a user partition corresponding to the site user,

wherein each user in the plurality of site users is defined by a combination of an email address and an identifier for the first site.

8. The computer program product of claim 7 , further comprising instructions executable by the processor to cause the processor to perform receiving at the multitenant platform a policy at an organization level of the organization hierarchy and pushing the policy to a site level.

9. The computer program product of claim 7 , further comprising instructions executable by the processor to cause the processor to perform enabling, by the multitenant platform, a single email address to be used to simultaneously access a first subscription of the first organization as a first user and a second subscription of a second organization as a second user, wherein access of the first user to the first subscription is isolated from access of the second user to the second subscription.

10. The computer program product of claim 7 , further comprising instructions executable by the processor to cause the processor to perform enabling, by the multitenant platform, a single email address to be used to simultaneously access a first subscription of the first organization as a first user and a second subscription of the first organization as a second user, wherein access of the first user to the first subscription is isolated from access of the second user to the second subscription.

11. The computer program product of claim 7 , wherein at least one of the plurality of user partitions includes an external user external to the first organization.

12. The computer program product of claim 7 , wherein at least one of the plurality of user partitions comprises a first user having an email address that has a domain which is different than a domain of the first site.

13. A system for controlling access to data in a multitenant environment, the system comprising:

a processor;

a data repository communicatively coupled to the processor;

a computer program product comprising a non-transitory computer-readable medium which stores instructions which are executable by the processor to cause the processor to perform:

providing a multitenant platform;

executing one or more applications on the multitenant platform;

defining an organization hierarchy on the multitenant platform, the organization hierarchy comprising a first organization at a first hierarchical level and a plurality of sites owned by the first organization at a second hierarchical level lower than the first hierarchical level, each of the plurality of sites representing a data isolation boundary for data of the first organization, each of the plurality of sites associated with one or more subscriptions to the one or more applications;

providing a user interface providing a unified view of the plurality of sites of the first organization;

enabling, by the multitenant platform, site-level subscription-based access to the one or more applications;

enabling, by the multitenant platform, the first organization to designate a plurality of user partitions within a first site of the plurality of sites, each user partition designating a corresponding set of site users and a corresponding authentication service;

enabling, by the multitenant platform, the first organization to authorize a plurality of site users associated with the first site to access the one or more applications associated with the one or more subscriptions associated with that site; and

for each site user of the plurality of site users associated with the first site, enabling, by the multitenant platform, access to each of the one or more subscriptions associated with the first site only if the site user is authenticated by the corresponding authentication service designated in a user partition corresponding to the site user,

wherein each user in the plurality of site users is defined by a combination of an email address and an identifier for the first site.

14. The system of claim 13 , further comprising instructions executable by the processor to cause the processor to perform receiving at the multitenant platform a policy at an organization level of the organization hierarchy and pushing the policy to a site level.

15. The system of claim 13 , further comprising instructions executable by the processor to cause the processor to perform enabling, by the multitenant platform, a single email address to be used to simultaneously access a first subscription of the first organization as a first user and a second subscription of a second organization as a second user, wherein access of the first user to the first subscription is isolated from access of the second user to the second subscription.

16. The system of claim 13 , further comprising instructions executable by the processor to cause the processor to perform enabling, by the multitenant platform, a single email address to be used to simultaneously access a first subscription of the first organization as a first user and a second subscription of the first organization as a second user, wherein access of the first user to the first subscription is isolated from access of the second user to the second subscription.

17. The system of claim 13 , wherein at least one of the plurality of user partitions includes an external user external to the first organization.

18. The system of claim 13 , wherein at least one of the plurality of user partitions comprises a first user having an email address that has a domain which is different than a domain of the first site.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 8, 2022
From: VARGA, PETER
To: OPEN TEXT SA ULC
Reel/Frame 062029/0677 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 20, 2022
From: SCOTT, NICHOLAS EDWARD
To: OPEN TEXT SA ULC
Reel/Frame 061490/0323 →
Continuity (1)
Related Publication 20210383005A1 · Dec 9, 2021
Cited By (1)
US 12,561,468