Hierarchical Cloud Identifier for Tenant Isolation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional techniques in cloud computing environments fail to provide effective classification and isolation of cloud providers, services, and tenants at the network layer, leading to inefficiencies in multi-tenancy, traffic management, and service awareness, particularly in scenarios involving multiple clouds and tenant/service mobility.
Innovation Solution
A generic hierarchical identification scheme using three-tuple cloud identifiers (cloud ID, service ID, and tenant ID) embedded in IP packets, along with an extended scheme that includes additional service deployment scheme-specific identifiers, enables fine-grained classification and isolation by distributing hierarchical classification information within the cloud provider and across networks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If conventional techniques are used for cloud computing, then implementation is simple, but classification and isolation of cloud providers, services, and tenants at the network layer cannot be achieved
Solution Approach 1:
The patent segments the cloud computing system into three distinct hierarchical layers: cloud provider identification, service identification, and tenant identification. Each layer is assigned a unique identifier (cloud ID, service ID, tenant ID) that can be independently managed and classified. This segmentation enables precise network-layer classification of traffic sources and destinations without requiring complex monolithic identification systems.
Solution Approach 2:
The patent implements a nested hierarchical structure where tenant IDs are nested within service IDs, which are in turn nested within cloud IDs. This nested doll approach allows multi-level classification and isolation: cloud providers contain multiple services, each service contains multiple tenants. The nested structure enables fine-grained control and identification at each level while maintaining overall system organization.
2Reliability
If multi-tenancy is implemented without per-cloud, per-service, and per-tenant classification, then system complexity is reduced, but effective isolation and management of multiple tenants and services cannot be achieved
Solution Approach 1:
The patent applies local quality by assigning specific identification and classification properties to different levels of the cloud hierarchy. Each cloud provider, service, and tenant has its own unique identifier and classification rules tailored to its specific requirements. This allows customized isolation and management policies at each level (cloud-level policies, service-level policies, tenant-level policies) without imposing a one-size-fits-all approach, thereby achieving effective isolation while managing complexity through localized solutions.
3Adaptability or versatility
If conventional network layer identification is used, then implementation is straightforward, but services configured with different service deployment schemes cannot be properly accounted for
Solution Approach 1:
The patent creates a universal hierarchical identification framework that can accommodate multiple service deployment schemes (IaaS, PaaS, SaaS, microservices, service function chaining) through a single multi-functional system. The three-tuple identifier structure (cloud ID, service ID, tenant ID) serves as a universal template that adapts to different deployment models without requiring separate identification mechanisms. This universal approach enables the system to handle diverse service configurations while maintaining consistent classification and isolation principles.
Data Source
AI summary
A cloud provider provides services to tenants over a network. Each cloud-based service is configured according to a respective service deployment scheme. The cloud provider maintains, for each service, classification information, including: a scheme type; a three-tuple cloud identifier including a cloud identifier, a service identifier, and a tenant identifier; and one or more scheme-specific service identifiers. The cloud provider distributes the classification information within the cloud provider, including to the services, to enable a respective tenant to exchange Internet Protocol (IP) packets with, and thereby access, a respective service and components of the service based on the classification information. The IP packet includes, for the respective service, the scheme type, the cloud identifier, the service identifier, the tenant identifier of the respective tenant, and the one or more scheme-specific service identifiers.


