Internal Gateway Switch for Multi-Tenant VLAN Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing virtualization technologies face limitations in resource isolation and network management in dense, heterogeneous tenant environments due to the limitations of VLAN technology, particularly in large-scale utility virtualization deployments, where the maximum number of unique VLAN IDs is insufficient and managing VLAN configurations becomes complex and costly.

Innovation Solution

A server system with an internal gateway/switch that manages data by maintaining tables correlating tenants with virtual servers and virtual gateways, using VLAN IDs for internal data access and communication, allowing for dynamic allocation and deallocation of virtual servers, and providing an internal VLAN for each server to enhance data isolation and network management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If VLAN technology is used to isolate tenant network traffic, then data isolation between tenants is achieved, but the maximum number of unique tenants is limited to 4094 VLAN IDs

Engineering Contradiction:
Improvedata isolationVSAvoidnumber of unique tenants
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent segments the VLAN ID space by introducing a tenant ID field separate from the VLAN ID field. Instead of using one VLAN ID per tenant, the system divides the identification space into two components: a tenant identifier ( Tenant ID) and a VLAN identifier. This segmentation allows multiple VLANs to serve a single tenant, dramatically increasing the number of supported tenants beyond the 4094 VLAN ID limit.

Inventive Principle:
Principle #1Segmentation

2Reliability

If VLAN IDs are managed directly at each switch, then network traffic isolation is maintained, but configuration becomes time-consuming and complex

Engineering Contradiction:
Improvenetwork traffic isolationVSAvoidconfiguration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary component (virtual switch or network controller) that manages VLAN configurations centrally rather than requiring direct configuration at each physical switch. This intermediary translates high-level tenant-to-VLAN mappings into switch-specific configurations, simplifying the overall system complexity while maintaining traffic isolation.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system enables automated VLAN configuration through the introduction of Tenant IDs. When a new tenant is added, the system can automatically allocate appropriate VLAN IDs and configure the necessary switch ports without manual intervention, reducing configuration complexity and time.

Inventive Principle:
Principle #25Self-service

3Reliability

If unique VLAN IDs are assigned to each organization, then traffic isolation is sufficient, but dynamic allocation and modification of tenancies becomes difficult and costly

Engineering Contradiction:
Improvetraffic isolationVSAvoiddynamic tenancy modification
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces dynamic tenancy support by separating Tenant IDs from VLAN IDs. This allows the system to dynamically allocate, modify, and deallocate VLANs for tenants without reconfiguring the entire network. Tenants can be added or removed, and VLAN assignments can be changed dynamically while maintaining isolation, making the system adaptable to changing business requirements.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS8670453B2Isolating network traffic in multi-tenant virtualization environments
Publication Date: 2014.03.11 EMC IP HLDG CO LLC
  • US8670453B2 patent drawing
  • US8670453B2 patent drawing
  • US8670453B2 patent drawing

AI summary

Managing data in a server system includes providing a plurality of servers, each having an internal gateway/switch that is accessible from outside the server, providing a plurality of virtual servers on at least some of the servers, where each of the virtual servers is accessible by the internal gateway/switch of the corresponding server, and accessing the data using the internal gateway/switch, where the internal gateway/switch determines which particular one of the virtual servers contain the data and then accesses the particular virtual server to provide the data. Managing data in a server system may also include associating portions of the data to tenants of the server system. Each of the servers may maintain a table that correlates tenants with the virtual servers maintained thereby and the internal gateway/switch may use the table to determine which particular one of the virtual servers contains data for a particular tenant.