US 11,722,457 B2
Secure multi-tenant cloud subscription sharing
Kalyan Kumar Kona, Redmond, WA (US); Qiwen Zheng, Sammamish, WA (US); and Darius Snapkauskas, Sammamish, WA (US)
Assigned to MICROSOFT TECHNOLOGY LICENSING, LLC, Redmond, WA (US)
Filed by MICROSOFT TECHNOLOGY LICENSING, LLC, Redmond, WA (US)
Filed on May 27, 2021, as Appl. No. 17/332,710.
Prior Publication US 2022/0385629 A1, Dec. 1, 2022
Int. Cl. G06F 15/16 (2006.01); H04L 9/40 (2022.01); H04L 67/52 (2022.01); H04L 47/70 (2022.01); H04L 67/10 (2022.01)
CPC H04L 63/0209 (2013.01) [H04L 47/827 (2013.01); H04L 67/10 (2013.01); H04L 67/52 (2022.05)] 20 Claims
OG exemplary drawing
 
1. A method comprising:
acquiring, by one or more processing units of a location-based manager of a cloud service provider that manages a set of cloud resources, a pool of subscriptions from a cloud platform configured to allocate the set of cloud resources to the cloud service provider, where each subscription defines a specific subset of the set of cloud resources allocated for use for a defined time period;
assigning, by the location-based manager of the cloud service provider, at least one subscription of the pool of subscriptions for a resource unit of the cloud platform, wherein the at least one subscription is shared by a plurality of tenants configured to request access to the specific subset of the set of cloud resources defined by the at least one subscription from the resource unit;
creating, by the location-based manager of the cloud service provider, a logical zone that defines a first security boundary between the resource unit and other resource units managed by the location-based manager, wherein the logical zone includes one or more second security boundaries that isolate individual tenants of the plurality of tenants from other tenants of the plurality of tenants that share the at least one subscription; and
deploying, by the location-based manager of the cloud service provider, the specific subset of the set of cloud resources associated with the at least one subscription within the logical zone for use by the resource unit on behalf of the plurality of tenants.