Dynamic Endpoint Group Binding for Cross-Tenant Resource Sharing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current multi-tenant software defined networks face inefficiencies in cross-tenant resource sharing due to the need for indirect communication through border leaf nodes, which is costly and not scalable, limiting the ability to share resources like image servers across tenants.

Innovation Solution

Implementing dynamic endpoint group (EPG) binding changes, such as altering EPG-to-endpoint or EPG-to-bridge domain bindings, to enable direct cross-tenant communication during resource access, triggered by traffic inspection or orchestration, allowing temporary access to shared resources without altering endpoints.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If indirect communication through border leaf nodes is used for cross-tenant resource sharing, then tenant isolation is maintained, but communication cost increases and scalability deteriorates

Engineering Contradiction:
Improvetenant isolationVSAvoidcommunication efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies dynamics by making EPG bindings changeable over time. The system dynamically modifies endpoint group bindings to temporarily allow direct cross-tenant communication when resource sharing is needed, then restores isolation afterward. This dynamic adjustment resolves the contradiction by allowing the system to switch between isolation and efficiency modes based on operational requirements.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system implements periodic action through time-limited binding changes. Cross-tenant access is granted temporarily for specific durations needed for resource access, then automatically revoked. This periodic granting and revoking of access rights allows efficient resource sharing while maintaining long-term tenant isolation, resolving the contradiction between continuous isolation and periodic efficiency needs.

Inventive Principle:
Principle #19Periodic action

2Productivity

If dynamic EPG binding changes are implemented for direct cross-tenant communication, then resource sharing efficiency improves, but system complexity increases

Engineering Contradiction:
Improveresource sharing efficiencyVSAvoidbinding management complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent implements feedback mechanisms where the system monitors resource access requests and automatically triggers binding changes when cross-tenant resource sharing is detected or requested. The system receives feedback about resource usage patterns and adjusts EPG bindings accordingly, then restores original bindings when sharing is complete. This automated feedback loop reduces the perceived complexity by making the system self-managing.

Inventive Principle:
Principle #23Feedback

3Speed

If direct cross-tenant communication is enabled, then access speed to shared resources improves, but security risks increase

Engineering Contradiction:
Improveaccess speedVSAvoidsecurity risk
Core Design Contradiction:
SpeedVSObject-affected harmful factors

Solution Approach 1:

The system applies preliminary anti-action by pre-establishing controlled binding states that allow direct communication only under specific conditions. Before enabling direct cross-tenant communication, the system validates the necessity and configures appropriate binding states that limit access to specific resources for specific time periods. This preliminary control measures prevent security risks while maintaining speed benefits.

Inventive Principle:
Principle #9Preliminary anti-action

Solution Approach 2:

The patent implements beforehand cushioning by creating temporary, limited-scope binding changes that cushion the security risk. Instead of permanent open access, the system creates time-bound, resource-specific binding states that act as a safety buffer. If security issues arise, the temporary nature of the binding changes limits potential damage while still providing fast access during the authorized window.

Inventive Principle:
Principle #11Beforehand cushioning (Prior cushioning)

Data Source

PatentUS10469402B2Dynamic endpoint group binding for cross-tenant resource sharing in software defined networks
Publication Date: 2019.11.05 CISCO TECHNOLOGY INC
  • US10469402B2 patent drawing
  • US10469402B2 patent drawing
  • US10469402B2 patent drawing

AI summary

The techniques presented herein use dynamic endpoint group (EPG) binding changes to facilitate cross-tenant resource sharing. A first node of a multi-tenant software defined network determines that an application on a first endpoint has initiated operation and needs temporary access to resources located at a second endpoint. The first and second endpoints are associated with first and second tenants, respectively, that are logically segregated from one another by the software defined network. The first node dynamically changes an initial EPG binding associated with the first endpoint to a second EPG binding that enables the first endpoint to temporarily directly access the resources at the second endpoint. The first node subsequently determines that the application on the first endpoint no longer needs access to the resources located at a second endpoint and, as such, changes the second EPG binding associated with the first endpoint back to the initial EPG binding.