Dynamic Endpoint Group Binding for Cross-Tenant Resource Sharing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current multi-tenant software defined networks face inefficiencies in cross-tenant resource sharing due to the need for indirect communication through border leaf nodes, which is costly and not scalable, limiting the ability to share resources like image servers across tenants.
Innovation Solution
Implementing dynamic endpoint group (EPG) binding changes, such as altering EPG-to-endpoint or EPG-to-bridge domain bindings, to enable direct cross-tenant communication during resource access, triggered by traffic inspection or orchestration, allowing temporary access to shared resources without altering endpoints.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If indirect communication through border leaf nodes is used for cross-tenant resource sharing, then tenant isolation is maintained, but communication cost increases and scalability deteriorates
Solution Approach 1:
The patent applies dynamics by making EPG bindings changeable over time. The system dynamically modifies endpoint group bindings to temporarily allow direct cross-tenant communication when resource sharing is needed, then restores isolation afterward. This dynamic adjustment resolves the contradiction by allowing the system to switch between isolation and efficiency modes based on operational requirements.
Solution Approach 2:
The system implements periodic action through time-limited binding changes. Cross-tenant access is granted temporarily for specific durations needed for resource access, then automatically revoked. This periodic granting and revoking of access rights allows efficient resource sharing while maintaining long-term tenant isolation, resolving the contradiction between continuous isolation and periodic efficiency needs.
2Productivity
If dynamic EPG binding changes are implemented for direct cross-tenant communication, then resource sharing efficiency improves, but system complexity increases
Solution Approach 1:
The patent implements feedback mechanisms where the system monitors resource access requests and automatically triggers binding changes when cross-tenant resource sharing is detected or requested. The system receives feedback about resource usage patterns and adjusts EPG bindings accordingly, then restores original bindings when sharing is complete. This automated feedback loop reduces the perceived complexity by making the system self-managing.
3Speed
If direct cross-tenant communication is enabled, then access speed to shared resources improves, but security risks increase
Solution Approach 1:
The system applies preliminary anti-action by pre-establishing controlled binding states that allow direct communication only under specific conditions. Before enabling direct cross-tenant communication, the system validates the necessity and configures appropriate binding states that limit access to specific resources for specific time periods. This preliminary control measures prevent security risks while maintaining speed benefits.
Solution Approach 2:
The patent implements beforehand cushioning by creating temporary, limited-scope binding changes that cushion the security risk. Instead of permanent open access, the system creates time-bound, resource-specific binding states that act as a safety buffer. If security issues arise, the temporary nature of the binding changes limits potential damage while still providing fast access during the authorized window.
Data Source
AI summary
The techniques presented herein use dynamic endpoint group (EPG) binding changes to facilitate cross-tenant resource sharing. A first node of a multi-tenant software defined network determines that an application on a first endpoint has initiated operation and needs temporary access to resources located at a second endpoint. The first and second endpoints are associated with first and second tenants, respectively, that are logically segregated from one another by the software defined network. The first node dynamically changes an initial EPG binding associated with the first endpoint to a second EPG binding that enables the first endpoint to temporarily directly access the resources at the second endpoint. The first node subsequently determines that the application on the first endpoint no longer needs access to the resources located at a second endpoint and, as such, changes the second EPG binding associated with the first endpoint back to the initial EPG binding.


