IP Library › Granted Patent US 12,373,587
Granted Patent B2
US 12,373,587 · App. 17/881,073 · Granted Jul 29, 2025

Maintaining data security in a multi-tenant microservice environment

Inventors: Muhammad Adeel (Edina, MN); Thomas Guzik (Edina, MN)
Assignees: Getac Technology Corporation; WHP Workflow Solutions, Inc.
G06F21/6218G06F16/2219
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,373,587
App. No.
17/881,073
Granted
Jul 29, 2025
Kind
B2
Abstract

A microservices platform that includes a plurality of microservices for providing data processing functions for data of multiple tenants may be implemented. Each tenant of the multiple tenants may be provided with an assigned binary large object (blob) data store in a blob storage platform that is only accessible by a corresponding tenant using a corresponding tenant identifier. Furthermore, each tenant of the multiple tenants may be assigned a corresponding local database at each microservice of the plurality of microservices that is only accessible by the corresponding tenant using the corresponding tenant identifier.

Claims (62)

1. One or more non-transitory computer-readable media storing computer-executable instructions that upon execution cause one or more processors to perform acts comprising:

implementing a microservices platform that includes a plurality of microservices for providing data processing functions for data of multiple tenants;

providing each tenant of the multiple tenants with an assigned binary large object (blob) data store in a blob storage platform that is only accessible by a corresponding tenant using a corresponding tenant identifier;

assigning each tenant of the multiple tenants a corresponding local database at each microservice of the plurality of microservices that is only accessible by the corresponding tenant using the corresponding tenant identifier; and

using metadata stored in the corresponding local database to access the assigned blob data store.

2. The one or more non-transitory computer-readable media of claim 1 , wherein the acts further comprise:

receiving, from a user device, a data processing request for one or more data files in which the data processing request is associated with a tenant identifier of a tenant;

retrieving particular metadata from a particular local database of a microservice in which the particular local database corresponds to tenant identifier received from the user device;

accessing a particular blob data store that is identified by the tenant identifier in relation to the one or more data files based at least on the particular metadata stored in the particular local database; and

performing data processing as requested in the data processing request on the one or more data files.

3. The one or more non-transitory computer-readable media of claim 2 , wherein the one or more data files are identified by the tenant identifier as belonging to the tenant, and wherein the performing includes storing the one or more data files in the particular blob data store, providing the user device with access to the one or more data files as stored in the particular blob data store, retrieving the one or more data files from the particular blob data store, modifying the one or more data files in the particular blob data store, or deleting the one or more data files from the particular blob data store.

4. The one or more non-transitory computer-readable media of claim 3 , wherein the one or more data files include a video file, providing includes providing an Azure shared access signature (SAS) token that enables the user device to playback the video file for a limited amount of time.

5. The one or more non-transitory computer-readable media of claim 4 , wherein the providing further includes providing the user device with access to the video file via the Azure SAS token and Azure private endpoints.

6. The one or more non-transitory computer-readable media of claim 2 , wherein the particular metadata includes database management data that enables at least one of access to the particular blob data store of the tenant or the one or more data files as stored in the particular blob data store.

7. The one or more non-transitory computer-readable media of claim 2 , wherein the particular blob data store is a cloud-based blob data store or a localized blob data store that is installed locally on a premise of the tenant.

8. The one or more non-transitory computer-readable media of claim 2 , wherein the receiving the data processing request includes:

receiving a data processing request that includes a user identifier of a user from a user device;

retrieving a tenant identifier that corresponds to the user identifier of the user;

associating the data processing request with the tenant identifier;

determining a particular microservice of the plurality of microservices that is to receive the data processing request based on one or more request parameters; and

routing the data processing request associated with the tenant identifier to the particular microservice such that the particular microservice executes the data processing request on data associated with the tenant identifier.

9. The one or more non-transitory computer-readable media of claim 8 , wherein the associating includes at least one of supplementing the data processing request with an additional data field that holds the tenant identifier or inserting the tenant identifier into a database connection string of the data processing request.

10. The one or more non-transitory computer-readable media of claim 8 , wherein the one or more request parameters include a data processing operation type identifier that matches a type of operation performed by the particular microservice.

11. The one or more non-transitory computer-readable media of claim 1 , wherein the acts further comprise:

receiving a search request for searching a multi-tenant search database for data related to a tenant, in which the data of the multiple tenants stored in the multi-tenant search database are indexed using the tenant identifiers of the multiple tenants; and

embedding a tenant identifier of the tenant in a database connection string of the search request to access the data related to the tenant.

12. The one or more non-transitory computer-readable media of claim 1 , wherein the multiple tenants include a plurality of law enforcement agencies.

13. A system, comprising:

one or more processors; and

memory including a plurality of computer-executable components that are executable by the one or more processors to perform a plurality of actions, the plurality of actions comprising:

implementing a microservices platform that includes a plurality of microservices for providing data processing functions for data of multiple tenants;

providing each tenant of the multiple tenants with an assigned binary large object (blob) data store in a blob storage platform that is only accessible by a corresponding tenant using a corresponding tenant identifier;

assigning each tenant of the multiple tenants a corresponding local database at each microservice of the plurality of microservices that is only accessible by the corresponding tenant using the corresponding tenant identifier; and

using metadata stored in the corresponding local database to access the assigned blob data store.

14. The system of claim 13 , wherein the plurality of actions further comprise:

receiving, from a user device, a data processing request for one or more data files in which the data processing request is associated with a tenant identifier of a tenant;

retrieving particular metadata from a particular local database of a microservice in which the particular local database corresponds to tenant identifier received from the user device;

accessing a particular blob data store that is identified by the tenant identifier in relation to the one or more data files based at least on the particular metadata stored in the particular local database; and

performing data processing as requested in the data processing request on the one or more data files.

15. The system of claim 14 , wherein the one or more data files are identified by the tenant identifier as belonging to the tenant, and wherein the performing includes storing the one or more data files in the particular blob data store, providing the user device with access to the one or more data files as stored in the particular blob data store, retrieving the one or more data files from the particular blob data store, modifying the one or more data files in the particular blob data store, or deleting the one or more data files from the particular blob data store.

16. The system of claim 14 , wherein the receiving the data processing request includes:

receiving a data processing request that includes a user identifier of a user from a user device;

retrieving a tenant identifier that corresponds to the user identifier of the user;

associating the data processing request with the tenant identifier;

determining a particular microservice of the plurality of microservices that is to receive the data processing request based on one or more request parameters; and

routing the data processing request associated with the tenant identifier to the particular microservice such that the particular microservice executes the data processing request on data associated with the tenant identifier.

17. The system of claim 16 , wherein the associating includes at least one of supplementing the data processing request with an additional data field that holds the tenant identifier or inserting the tenant identifier into a database connection string of the data processing request.

18. The system of claim 16 , wherein the one or more request parameters include a data processing operation type identifier that matches a type of operation performed by the particular microservice.

19. A computer-implemented method, comprising:

implementing a microservices platform that includes a plurality of microservices for providing data processing functions for data of multiple tenants;

providing each tenant of the multiple tenants with an assigned binary large object (blob) data store in a blob storage platform that is only accessible by a corresponding tenant using a corresponding tenant identifier;

assigning each tenant of the multiple tenants a corresponding local database at each microservice of the plurality of microservices that is only accessible by the corresponding tenant using the corresponding tenant identifier;

receiving, from a user device, a data processing request for one or more data files in which the data processing request is associated with a tenant identifier of a tenant;

retrieving metadata from a particular local database of a microservice in which the particular local database corresponds to tenant identifier received from the user device;

accessing a particular blob data store that is identified by the tenant identifier in relation to the one or more data files based at least on the metadata stored in the particular local database; and

performing data processing as requested in the data processing request on the one or more data files.

20. The computer-implemented method of claim 19 , wherein the receiving the data processing request includes:

receiving a data processing request that includes a user identifier of a user from a user device;

retrieving a tenant identifier that corresponds to the user identifier of the user;

associating the data processing request with the tenant identifier;

determining a particular microservice of the plurality of microservices that is to receive the data processing request based on one or more request parameters; and

routing the data processing request associated with the tenant identifier to the particular microservice such that the particular microservice executes the data processing request on data associated with the tenant identifier.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 4, 2022
From: ADEEL, MUHAMMAD; GUZIK, THOMAS
To: GETAC TECHNOLOGY CORPORATION; WHP WORKFLOW SOLUTIONS, INC.
Reel/Frame 060721/0705 →
Continuity (1)
Related Publication 20240045980A1 · Feb 8, 2024
References Cited (46)
US 9043196B1 · Leydon et al. · 2015 [cited by applicant]
US 9508048B2 · Said · 2016 [cited by examiner]
US 11032164B1 · Rothschild et al. · 2021 [cited by applicant]
US 11457080B1 · Meduri et al. · 2022 [cited by applicant]
US 11563636B1 · Kairali et al. · 2023 [cited by applicant]
US 20120173589A1 · Kwon · 2012 [cited by examiner]
US 20160087941A1 · Mudigonda · 2016 [cited by examiner]
US 20160124742A1 · Rangasamy et al. · 2016 [cited by applicant]
US 20160292236A1 · Joshi · 2016 [cited by examiner]
US 20180255009A1 · Chen et al. · 2018 [cited by applicant]
US 20190034460A1 · Eberlein · 2019 [cited by examiner]
US 20190087835A1 · Schwed · 2019 [cited by examiner]
US 20190095498A1 · Srinivasan et al. · 2019 [cited by applicant]
US 20190273746A1 · Coffing · 2019 [cited by applicant]
US 20200036789A1 · Mehta et al. · 2020 [cited by applicant]
US 20200042365A1 · Tanna et al. · 2020 [cited by applicant]
US 20200117477A1 · Aly et al. · 2020 [cited by applicant]
US 20200264860A1 · Srinivasan · 2020 [cited by examiner]
US 20200265062A1 · Srinivasan · 2020 [cited by examiner]
US 20200162380A1 · Pilkington et al. · 2020 [cited by applicant]
US 20200379829A1 · Vasilevskiy · 2020 [cited by examiner]
US 20210218819A1 · Lawson et al. · 2021 [cited by applicant]
US 20210240544A1 · Ramachandran et al. · 2021 [cited by applicant]
US 20210258212A1 · Uke · 2021 [cited by examiner]
US 20210326365A1 · Moser · 2021 [cited by examiner]
US 20210336872A1 · Singh et al. · 2021 [cited by applicant]
US 20210374028A1 · Kruempelmann · 2021 [cited by examiner]
US 20220014459A1 · Ganguli et al. · 2022 [cited by applicant]
US 20220027828A1 · Avala · 2022 [cited by examiner]
US 20220121566A1 · Bernat et al. · 2022 [cited by applicant]
US 20220150666A1 · Kozhaya et al. · 2022 [cited by applicant]
US 20220164701A1 · Shrivastava · 2022 [cited by examiner]
US 20220224637A1 · Deepak et al. · 2022 [cited by applicant]
US 20220342718A1 · Iqbal · 2022 [cited by examiner]
US 20220417219A1 · Sheriff et al. · 2022 [cited by applicant]
US 20230016946A1 · Wouhaybi et al. · 2023 [cited by applicant]
US 20230259415A1 · Kairali et al. · 2023 [cited by applicant]
US 20230266972A1 · Rogers et al. · 2023 [cited by applicant]
US 20230289158A1 · Sipcic · 2023 [cited by examiner]
US 20240244114A1 · Soni · 2024 [cited by examiner]
KR 20180028520A · 2018 [cited by applicant]
KR 20190045049A · 2019 [cited by applicant]
KR 102050188B1 · 2019 [cited by applicant]
International Application No. PCT/2023/028878, International Search Report and Written Opinion mailed Nov. 14, 2023, 11 pages. [cited by applicant]
International Application No. PCT/US2023/028873, International Search Report and Written Opinion mailed Nov. 15, 2023, 8 pages. [cited by applicant]
U.S. Appl. No. 17/880,991, Notice of Allowance mailed Oct. 17, 2023, 29 pages. [cited by applicant]