Edge Router Segmentation via Hash Entries for Multi-Tenant Cloud Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In multi-tenanted networks, existing technologies fail to preserve segmentation information on transport connections when routing traffic to Secured Internet Gateways (SIGs), leading to shared transport connections across all network segments without differentiation.

Innovation Solution

The implementation of a method that uses reference tables with hash entries to uniquely identify and route traffic from multiple network segments through unique transport tunnels, ensuring segmentation is maintained across the multi-tenanted network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Use of energy by moving object

If a shared transport connection is used for all network segments, then resource utilization is improved, but segmentation information is lost and security differentiation is reduced

Engineering Contradiction:
Improveresource utilizationVSAvoidsegmentation information
Core Design Contradiction:
Use of energy by moving objectVSLoss of information

Solution Approach 1:

The patent divides the network traffic into separate segments based on network segment identifiers and uses hash entries to map each segment to specific transport connections. This allows different network segments to be handled differently even when sharing infrastructure, preserving segmentation information while utilizing shared resources.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies different routing policies and security configurations to different network segments locally. Each segment receives appropriate security treatment based on its specific requirements while sharing the overall transport infrastructure, achieving both resource efficiency and security differentiation.

Inventive Principle:
Principle #3Local quality

2Reliability

If unique transport tunnels are created for each network segment, then segmentation is preserved and security differentiation is improved, but device complexity and resource consumption increase

Engineering Contradiction:
Improvesegmentation preservationVSAvoidtransport connection management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates a universal hash table structure that can handle multiple network segments and transport connections simultaneously. This single data structure serves all segmentation requirements, reducing the complexity that would otherwise arise from managing separate routing tables for each segment.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent uses hash entries that copy essential segmentation information from original network packets into a compact format. This allows the system to maintain segmentation state without duplicating entire packet copies or maintaining complex separate routing structures for each segment.

Inventive Principle:
Principle #26Copying

3Measurement precision

If hash entries are maintained in reference tables for traffic routing, then segmentation accuracy is improved, but memory usage and processing overhead increase

Engineering Contradiction:
Improvetraffic identification accuracyVSAvoidmemory resources
Core Design Contradiction:
Measurement precisionVSQuantity of substance

Solution Approach 1:

The patent implements hash entries with limited lifetimes that are automatically removed after use. This allows the system to create precise routing mappings when needed while automatically cleaning up memory resources, achieving high identification accuracy without permanent memory overhead for all possible segment combinations.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Data Source

PatentUS20250202818A1Enabling differentiated multi-segment cloud security for tenants on a multi-tenant edge device
Publication Date: 2025.06.19 CISCO TECHNOLOGY INC
  • US20250202818A1 patent drawing
  • US20250202818A1 patent drawing
  • US20250202818A1 patent drawing

AI summary

Edge router may receive, from a tenant of a multi-tenanted network, a request to access a Secured Internet Gateway (SIG) service associated with a cloud provider. The edge router may access one or more reference tables and add one or more hash entries to the one or more reference tables. The one or more hash entries includes one or more identifiers associated with the request. The edge router may transmit the request to the SIG service. The edge router may receive a response from the SIG service and may transmit the response to the tenant of the multi-tenanted network according to the one or more hash entries of the one or more reference tables.