Hierarchical Cloud Identifier Scheme for Tenant Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional techniques in cloud computing environments fail to effectively classify and isolate cloud providers, services, and tenants at the network layer, leading to insufficient multi-tenancy and increased latency due to reliance on IP prefixes, VLANs, and deep-packet-inspection methods.

Innovation Solution

A hierarchical classification scheme using cloud-identifiers, service-identifiers, and tenant-identifiers embedded in IP packets, similar to the Digital Object Identifier scheme, to uniquely identify and manage cloud providers, services, and tenants, enabling fine-grained isolation and access control.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If conventional classification techniques (IP prefixes, VLANs, deep-packet-inspection) are used, then network layer classification is achieved, but classification precision and isolation effectiveness deteriorate

Engineering Contradiction:
Improveclassification precisionVSAvoidclassification complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the classification system into three distinct hierarchical layers: cloud provider identifiers, service identifiers, and tenant identifiers. Each layer operates independently at the network packet level, allowing precise classification without complex deep-packet-inspection. This segmentation enables fine-grained isolation while maintaining system simplicity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a new dimension of classification by embedding multiple identifier fields directly into network packets at the network layer, rather than relying on traditional IP address hierarchies or higher-layer protocols. This dimensional expansion allows simultaneous classification by cloud provider, service, and tenant without increasing operational complexity.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Measurement precision

If deep-packet-inspection methods are used, then classification capability is improved, but processing speed and latency worsen

Engineering Contradiction:
Improveclassification capabilityVSAvoidprocessing speed
Core Design Contradiction:
Measurement precisionVSSpeed

Solution Approach 1:

The patent performs classification actions at the network packet level using pre-defined identifier fields embedded in packets, rather than inspecting packet contents. This preliminary structuring of identification data enables rapid matching and routing decisions without time-consuming deep-packet-inspection, thereby maintaining high processing speed while achieving precise classification.

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If IP prefixes and VLANs are used for isolation, then network layer classification is achieved, but multi-tenancy isolation effectiveness deteriorates

Engineering Contradiction:
Improveisolation implementationVSAvoidisolation effectiveness
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent applies local quality by assigning specific identifier fields to different hierarchical levels: cloud provider identifiers for broad isolation, service identifiers for intermediate segmentation, and tenant identifiers for fine-grained isolation. This localized assignment of identification functions at each hierarchical level enables effective multi-tenancy isolation while maintaining ease of operation through standardized packet field usage.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS9729406B2Cloud provider, service, and tenant classification in cloud computing
Publication Date: 2017.08.08 CISCO TECHNOLOGY INC
  • US9729406B2 patent drawing
  • US9729406B2 patent drawing
  • US9729406B2 patent drawing

AI summary

A cloud provider supports cloud-based services accessible to tenants of the cloud provider over a network. In the cloud provider, classification information including a cloud-identifier to identify the cloud provider, service-identifiers each to identify a respective one of the services, and tenant-identifiers each to identify a respective one of the tenants is maintained. The classification information is distributed within the cloud provider, including to the services, and may also be distributed outside of the cloud provider, to enable a respective tenant to exchange IP packets with, and thereby access, a respective service based on the classification information, wherein each IP packet includes the cloud-identifier, the service-identifier of the respective service, and the tenant-identifier of the respective tenant.