Hierarchical Cloud Identifier for Tenant Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional techniques in cloud computing environments fail to provide effective classification and isolation of cloud providers, services, and tenants at the network layer, leading to inefficiencies in multi-tenancy, traffic management, and service awareness, particularly in scenarios involving multiple clouds and tenant/service mobility.

Innovation Solution

A generic hierarchical identification scheme using three-tuple cloud identifiers (cloud ID, service ID, and tenant ID) embedded in IP packets, along with an extended scheme that includes additional service deployment scheme-specific identifiers, enables fine-grained classification and isolation by distributing hierarchical classification information within the cloud provider and across networks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If conventional techniques are used for cloud computing, then implementation is simple, but classification and isolation of cloud providers, services, and tenants at the network layer cannot be achieved

Engineering Contradiction:
Improveclassification precisionVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the cloud computing system into three distinct hierarchical layers: cloud provider identification, service identification, and tenant identification. Each layer is assigned a unique identifier (cloud ID, service ID, tenant ID) that can be independently managed and classified. This segmentation enables precise network-layer classification of traffic sources and destinations without requiring complex monolithic identification systems.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements a nested hierarchical structure where tenant IDs are nested within service IDs, which are in turn nested within cloud IDs. This nested doll approach allows multi-level classification and isolation: cloud providers contain multiple services, each service contains multiple tenants. The nested structure enables fine-grained control and identification at each level while maintaining overall system organization.

Inventive Principle:
Principle #7Nested doll (Nesting)

2Reliability

If multi-tenancy is implemented without per-cloud, per-service, and per-tenant classification, then system complexity is reduced, but effective isolation and management of multiple tenants and services cannot be achieved

Engineering Contradiction:
Improveisolation effectivenessVSAvoidclassification system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies local quality by assigning specific identification and classification properties to different levels of the cloud hierarchy. Each cloud provider, service, and tenant has its own unique identifier and classification rules tailored to its specific requirements. This allows customized isolation and management policies at each level (cloud-level policies, service-level policies, tenant-level policies) without imposing a one-size-fits-all approach, thereby achieving effective isolation while managing complexity through localized solutions.

Inventive Principle:
Principle #3Local quality

3Adaptability or versatility

If conventional network layer identification is used, then implementation is straightforward, but services configured with different service deployment schemes cannot be properly accounted for

Engineering Contradiction:
Improveservice deployment scheme adaptabilityVSAvoididentification scheme complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent creates a universal hierarchical identification framework that can accommodate multiple service deployment schemes (IaaS, PaaS, SaaS, microservices, service function chaining) through a single multi-functional system. The three-tuple identifier structure (cloud ID, service ID, tenant ID) serves as a universal template that adapts to different deployment models without requiring separate identification mechanisms. This universal approach enables the system to handle diverse service configurations while maintaining consistent classification and isolation principles.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10367735B2Cloud provider classification for different service deployment schemes
Publication Date: 2019.07.30 CISCO TECHNOLOGY INC
  • US10367735B2 patent drawing
  • US10367735B2 patent drawing
  • US10367735B2 patent drawing

AI summary

A cloud provider provides services to tenants over a network. Each cloud-based service is configured according to a respective service deployment scheme. The cloud provider maintains, for each service, classification information, including: a scheme type; a three-tuple cloud identifier including a cloud identifier, a service identifier, and a tenant identifier; and one or more scheme-specific service identifiers. The cloud provider distributes the classification information within the cloud provider, including to the services, to enable a respective tenant to exchange Internet Protocol (IP) packets with, and thereby access, a respective service and components of the service based on the classification information. The IP packet includes, for the respective service, the scheme type, the cloud identifier, the service identifier, the tenant identifier of the respective tenant, and the one or more scheme-specific service identifiers.