US2018218169A1PendingUtilityA1
Security and data isolation for tenants in a business data system
Assignee: MICROSOFT TECHNOLOGY LICENSING LLCPriority: Jul 30, 2012Filed: Mar 15, 2018Published: Aug 2, 2018
Est. expiryJul 30, 2032(~6 yrs left)· nominal 20-yr term from priority
G06F 21/6227G06F 21/604G06F 21/6245
50
PatentIndex Score
0
Cited by
0
References
0
Claims
Abstract
A multi-tenant hosting system receives business data and tenant-identifying data, from a tenant. The data from multiple different tenants is stored on a single database, but the data corresponding to each tenant is partitioned by marketing the data with a partition identifier, within the database. Therefore, the hosting system only allows individual tenants to have access to their own data.
Claims
exact text as granted — not AI-modified1 - 20 . (canceled)
21 . A computing system comprising:
a processor; and memory storing instructions executable by the processor, wherein the instructions, when executed, configure the computing system to:
store, in a multi-tenant data store, first data in association with a first tenant and second data in association with a second tenant, wherein
based on the associations, the first data is partitioned from the second data to restrict access to the first data by the second tenant;
receive a data manipulation request that is associated with a requesting client and includes tenant identification data;
based on the tenant identification data, determine that the requesting client is associated with the first tenant; and
based on determining that the requesting client is associated with the first tenant, service the data manipulation request by confining the data manipulation request to data stored in association with the first tenant.
22 . The computing system of claim 21 , wherein the first and second data correspond to an application associated with the computing system.
23 . The computing system of claim 21 , wherein the instructions configure the computing system to:
access the security rule for the first tenant, based on the tenant identification data in the data manipulation request; and implement the security rule for the first tenant while servicing the data manipulation request.
24 . The computing system of claim 21 , wherein the instructions configure the computing system to:
receive a request to store data in the multi-tenant data store.
25 . The computing system of claim 24 , wherein the instructions configure the computing system to:
store the data in the multi-tenant data store; and mark the data stored in the multi-tenant data store with a partition identifier indicating that the data belongs to the first tenant.
26 . The computing system of claim 25 , wherein the instructions configure the computing system to:
mark each of one or more tables containing the data in the multi-tenant data store with the partition identifier.
27 . The computing system of claim 26 , wherein each table has at least one row, and the instructions configure the computing system to:
mark each row in each table with the partition identifier.
28 . The computing system of claim 21 , wherein the data manipulation request identifies data in the multi-tenant data store to be accessed, the identified data including data from both the first and second tenants.
29 . The computing system of claim 28 , wherein the instructions configure the computing system to:
modify the data manipulation request to obtain a modified data manipulation request that defines only data belonging to the first tenant; and service the modified data manipulation request.
30 . The computing system claim 29 wherein the instructions configure the computing system to:
receive a query for data that encompasses data from both the first and second tenants; and
modify the query to return only data identified by the partition identifier as belonging to the first tenant.
31 . The computing system of claim 21 , wherein the instructions configure the computing system to provide:
a server layer configured to host a same application for the first and second tenants.
32 . The computing system of claim 21 , wherein the instructions configure the computing system to:
maintain a separate copy of cached data, in cache memory, for each tenant.
33 . The computing system of claim 32 wherein the data manipulation request comprises a query requesting data, and wherein the instructions configure the computing system to:
store the requested data in a cache memory that stores only cached data for the first tenant.
34 . A method performed by a computing system, the method comprising:
receiving a data manipulation request that is associated with a requesting client and includes tenant identification data, wherein
a multi-tenant data store associated with the computing system stores first data in association with a first tenant and second data in association with a second tenant, and
based on the associations, the first data is partitioned from the second data to restrict access to the first data by the second tenant:
based on the tenant identification data, determining that the requesting client is associated with the first tenant; and based on determining that the requesting client is associated with the first tenant, servicing the data manipulation request by confining the data manipulation request to data stored in association with the first tenant.
35 . The method of claim 34 , wherein the first and second data correspond to an application associated with the computing system, and the method further comprising:
accessing a security rule associated with the first tenant, based on the tenant identification data in the data manipulation request; and implementing the security rules for the first tenant while servicing the data manipulation request.
36 . The method of claim 34 , wherein receiving the data manipulation request comprises:
receiving a request to store data on the multi-tenant data store; storing the data in the multi-tenant data store; and marking the data stored in the multi-tenant data store with a partition identifier indicating that the data belongs to the first tenant.
37 . The method of claim 34 , wherein the data manipulation request identifies data in the multi-tenant data store to be accessed, the identified data including data from both the first and second tenants, the method comprising:
modifying the data manipulation request to obtain a modified data manipulation request that defines only data belonging to the first tenant; and servicing the modified data manipulation request.
38 . A method performed by a client computing device, the method comprising:
generating a tenant identifier that is based on configuration data associated with the client computing device and identifies the client computing device as being associated with a particular tenant in a multi-tenant computing system,
the multi-tenant computing system configured to store, in a multi-tenant data store, first data in association with the particular tenant and second data in association with another tenant, other than the particular tenant, the first data being partitioned from the second data to restrict access to the first data by the other tenant;
sending, to the multi-tenant computing system, a data request that includes the tenant identifier and requests a data operation on the multi-tenant data store; and receiving, from the multi-tenant computing system, a response to the data request that includes a result of the data operation.
39 . The method of claim 38 , wherein data operation comprises at least one of:
a data storage request; or a data access request.
40 . The method of claim 38 , and further comprising:
receiving the configuration data; and storing the configuration data in association with the client computing device.Join the waitlist — get patent alerts
Track US2018218169A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.