Multi-tenant Cloud Network Segmentation via IP Range Allocation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Constructing multi-tenant multi-region cloud networks that ensure privacy and security for multiple companies or organizations sharing the same platform is challenging due to the need for isolated and exclusive private virtual networks.

Innovation Solution

A system and method for configuring a segmented cloud-based network using separate Internet Protocol (IP) segments, where processors receive instructions to create additional private virtual networks, calculate non-conflicting IP address ranges, allocate these ranges, and deploy gateways to connect client devices, applying Layer 2 or Layer 3 routing and security measures to ensure isolation and security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If multiple companies share the same cloud platform to construct private virtual networks, then resource utilization and scalability are improved, but security and privacy isolation become more difficult to ensure

Engineering Contradiction:
Improvemulti-tenant capabilityVSAvoidsecurity isolation
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The cloud network is segmented into multiple isolated virtual networks, each assigned to a different tenant. IP address segmentation is used to divide the network into distinct segments, with each segment representing a private virtual network that is logically isolated from other segments. This allows multiple tenants to share the same physical infrastructure while maintaining security and privacy isolation through network layer segmentation.

Inventive Principle:
Principle #1Segmentation

2Reliability

If separate private virtual networks are created for each tenant, then security and privacy are improved, but system complexity and configuration difficulty increase

Engineering Contradiction:
Improvesecurity isolationVSAvoidnetwork configuration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system implements automated IP address allocation and network configuration services that allow tenants to self-provision private virtual networks without manual intervention. The network automatically calculates non-conflicting IP address ranges, configures routing tables, and sets up network policies based on tenant requirements, eliminating the need for complex manual configuration while maintaining security isolation.

Inventive Principle:
Principle #25Self-service

3Reliability

If manual configuration of IP address ranges and routing is performed for each new virtual network, then security control is improved, but deployment time and operational overhead increase

Engineering Contradiction:
Improvesecurity controlVSAvoidnetwork deployment speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system pre-calculates and reserves IP address ranges for different network segments before actual deployment. Routing tables and network policies are pre-configured with security rules and access control parameters. When a new virtual network is requested, the system automatically allocates pre-prepared IP ranges and applies pre-defined security templates, enabling rapid deployment while maintaining security control without manual configuration.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11888815B2Scalable and on-demand multi-tenant and multi region secure network
Publication Date: 2024.01.30 CHECK POINT SOFTWARE TECH LTD
  • US11888815B2 patent drawing
  • US11888815B2 patent drawing

AI summary

Provided herein are systems and methods for configuring a segmented cloud based network based on separate Internet Protocol (IP) segments, comprising receiving instructions to create one or more additional private virtual networks as respective additional segments in a multi-tenant multi-regional cloud based network segmented to a plurality of segments each mapped by a respective IP address range, calculating one or more non-conflicting new IP address range based on analysis of the IP address range of each of the segments, allocating a respective new IP address range to each additional segment, and deploying automatically one or more gateways. The gateways are configured to connect one or more client devices to the additional segment(s) by assigning each client device an IP address in the respective new IP address range and routing network packets between the client devices and the respective additional segment according to mapping of the respective new IP address range.