Edge Router Segmentation via Hash Entries for Multi-Tenant Cloud Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In multi-tenanted networks, existing technologies fail to preserve segmentation information on transport connections when routing traffic to Secured Internet Gateways (SIGs), leading to shared transport connections across all network segments without differentiation.
Innovation Solution
The implementation of a method that uses reference tables with hash entries to uniquely identify and route traffic from multiple network segments through unique transport tunnels, ensuring segmentation is maintained across the multi-tenanted network.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Use of energy by moving object
If a shared transport connection is used for all network segments, then resource utilization is improved, but segmentation information is lost and security differentiation is reduced
Solution Approach 1:
The patent divides the network traffic into separate segments based on network segment identifiers and uses hash entries to map each segment to specific transport connections. This allows different network segments to be handled differently even when sharing infrastructure, preserving segmentation information while utilizing shared resources.
Solution Approach 2:
The patent applies different routing policies and security configurations to different network segments locally. Each segment receives appropriate security treatment based on its specific requirements while sharing the overall transport infrastructure, achieving both resource efficiency and security differentiation.
2Reliability
If unique transport tunnels are created for each network segment, then segmentation is preserved and security differentiation is improved, but device complexity and resource consumption increase
Solution Approach 1:
The patent creates a universal hash table structure that can handle multiple network segments and transport connections simultaneously. This single data structure serves all segmentation requirements, reducing the complexity that would otherwise arise from managing separate routing tables for each segment.
Solution Approach 2:
The patent uses hash entries that copy essential segmentation information from original network packets into a compact format. This allows the system to maintain segmentation state without duplicating entire packet copies or maintaining complex separate routing structures for each segment.
3Measurement precision
If hash entries are maintained in reference tables for traffic routing, then segmentation accuracy is improved, but memory usage and processing overhead increase
Solution Approach 1:
The patent implements hash entries with limited lifetimes that are automatically removed after use. This allows the system to create precise routing mappings when needed while automatically cleaning up memory resources, achieving high identification accuracy without permanent memory overhead for all possible segment combinations.
Data Source
AI summary
Edge router may receive, from a tenant of a multi-tenanted network, a request to access a Secured Internet Gateway (SIG) service associated with a cloud provider. The edge router may access one or more reference tables and add one or more hash entries to the one or more reference tables. The one or more hash entries includes one or more identifiers associated with the request. The edge router may transmit the request to the SIG service. The edge router may receive a response from the SIG service and may transmit the response to the tenant of the multi-tenanted network according to the one or more hash entries of the one or more reference tables.


