发明名称 SECURE ISOLATION OF TENANT RESOURCES IN A MULTI-TENANT STORAGE SYSTEM USING A SECURITY GATEWAY
摘要 Machines, systems and methods for handling a client request in a hierarchical multi-tenant data storage system, the method comprising processing a request in subtasks, wherein a subtask is executed with a minimal set of privileges associated with a specific subtenant; extracting a claimed n-level hierarchy of a tenant and sub-tenant identities from the request; extracting authentication signatures or credentials that correspond to a level in the hierarchy; for a first level in the hierarchy, sending the request to a dedicated subtenant authenticator with privilege to validate credentials for a subtenant at the first level; and receiving a confirmation from the dedicated subtenant authenticator, whether the request is authentic.
申请公布号 US2016259807(A1) 申请公布日期 2016.09.08
申请号 US201615156821 申请日期 2016.05.17
申请人 International Business Machines Corporation 发明人 Factor Michael E.;Hadas David;Kolodner Elliot K.;Kurmus Anil;Shulman-Peleg Alexandra;Sorniotti Alessandro
分类号 G06F17/30;H04L29/06 主分类号 G06F17/30
代理机构 代理人
主权项 1. A method of maintaining resource isolation in a multi-tenant computing system, the method comprising: receiving a first request submitted by a first user in a multi-tenant computing system; extracting from the first request a first tenant ID associated with a tenant from among a plurality of tenants in the multi-tenant computing system; spawning a first request processor, wherein the first tenant ID is utilized by the first request processor to determine resource access privileges associated with the first tenant ID; spawning a subtenant authenticator; examining, by the subtenant authenticator, user credential data associated with the first request to determine whether the first user is authorized to access the one or more target resources; and servicing the first request by providing access to one or more target resources identified in the first request, in response to determining that the first tenant ID is associated with a first tenant with privileges to access the one or more target resources.
地址 Armonk NY US